[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/api-proxy:0.28.1
- Dominant language
- Go
- Stars
- 5.1k
- Forks
- 541
- Avg merge
- 5h 48m
- Merged PRs (30d)
- 773
Description
### Overview
Daily container scan findings for `ghcr.io/github/gh-aw-firewall/api-proxy:0.28.1` (pinned `sha256:288e7d2a12d5b430500d739f9c16e20bb1ed51b91f986f3f3eccde189f489f5c`).
### Key metrics
| Severity | Count |
|---|---|
| Critical | 0 |
| High | 3 |
| Medium | 11 |
| Low | 0 |
| Negligible | 0 |
| Unknown | 0 |
| License violations | 1 |
### Vulnerabilities
High (3)
| CVE/GHSA | Package | Fixed version |
|---|---|---|
| GHSA-rgw5-rvv9-x895 | brace-expansion@5.0.7 | 5.0.9 |
| GHSA-mh99-v99m-4gvg | brace-expansion@5.0.7 | 5.0.8 |
| GHSA-mwp4-54f8-5fhr | ip-address@10.2.0 | 10.3.1 |
Medium (11)
| CVE/GHSA | Package | Fixed version |
|---|---|---|
| GHSA-8988-4f7v-96qf | `@opentelemetry/core`@1.30.1 | 2.8.0 |
| CVE-2025-60876 | busybox@1.37.0-r31 | none published |
| CVE-2025-60876 | busybox-binsh@1.37.0-r31 | none published |
| CVE-2025-60876 | ssl_client@1.37.0-r31 | none published |
| GHSA-4xrf-jv44-h6hh | ip-address@10.2.0 | 10.2.2 |
| GHSA-22jq-vg5j-6vgg | ip-address@10.2.0 | 10.2.1 |
| CVE-2026-58055 | nghttp2-libs@1.69.0-r0 | none published |
| GHSA-8xcm-r25x-g524 | undici@6.27.0 | 6.28.0 |
| GHSA-v3r7-h72x-cjcm | undici@6.27.0 | 6.28.0 |
| GHSA-m8rv-5g2x-5cg5 | undici@6.27.0 | 6.28.0 |
| GHSA-r292-9mhp-454m | tar@7.5.19 | 7.5.21 |
### License violations
License violations (1)
| Package | License |
|---|---|
| awf-api-proxy@1.0.0 | no licenses found |
### Next actions
- Bump `brace-expansion`, `ip-address`, `undici`, `tar`, and `@opentelemetry/core` to the fixed versions listed above.
- `busybox`/`ssl_client`/`nghttp2-libs` fixes are pending upstream Alpine advisories; track and rebuild once patched packages are published.
- `awf-api-proxy@1.0.0` has no declared license metadata — add a `license` field to its `package.json` (or confirm intended license) to resolve the policy violation.
- This image is rebuilt weekly via the daily `gh aw compile --force-refresh-container-pins` job; a pin-refresh PR is the default remediation path for transitive dependency bumps.
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/31929401072) · auto · 438.5 AIC · ⌖ 15.1 AIC · ⊞ 7.2K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
Contributor guide
Assessment
This issue has not been assessed yet.