github / github/gh-aw

[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.1

Open
#53,072 1 comment 1 reaction 2 assignees Claimed by @pelikhan View on GitHub
cookie security
Dominant language
Go
Stars
5.1k
Forks
541
Avg merge
5h 48m
Merged PRs (30d)
773

Description

### Overview

Daily container scan findings for `ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.1` (pinned `sha256:f931e5e1e13f765605d03ef9511fc755d779a51b76581ea14586e9871506a610`).

### Key metrics

| Severity | Count |
|---|---|
| Critical | 0 |
| High | 9 |
| Medium | 12 |
| Low | 0 |
| Negligible | 0 |
| Unknown | 0 |
| License violations | 1 |

### Vulnerabilities

High (9)

| CVE/GHSA | Package | Fixed version |
|---|---|---|
| GO-2026-5026 | stdlib@go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
| GHSA-rgw5-rvv9-x895 | brace-expansion@5.0.7 | 5.0.9 |
| GO-2026-5942 | stdlib@go1.26.5 | 1.26.6, 1.27.0-rc.3 |
| GHSA-mh99-v99m-4gvg | brace-expansion@5.0.7 | 5.0.8 |
| GHSA-mwp4-54f8-5fhr | ip-address@10.2.0 | 10.3.1 |
| GO-2026-6089 | stdlib@go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
| GO-2026-6088 | stdlib@go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
| GO-2026-6090 | stdlib@go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
| GO-2026-5972 | stdlib@go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 |

Medium (12)

| CVE/GHSA | Package | Fixed version |
|---|---|---|
| CVE-2025-60876 | busybox@1.37.0-r31 | none published |
| CVE-2025-60876 | busybox-binsh@1.37.0-r31 | none published |
| CVE-2025-60876 | ssl_client@1.37.0-r31 | none published |
| GHSA-4xrf-jv44-h6hh | ip-address@10.2.0 | 10.2.2 |
| GHSA-22jq-vg5j-6vgg | ip-address@10.2.0 | 10.2.1 |
| CVE-2026-58055 | nghttp2-libs@1.69.0-r0 | none published |
| GO-2026-6091 | stdlib@go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
| GO-2026-6218 | stdlib@go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
| GHSA-8xcm-r25x-g524 | undici@6.27.0 | 6.28.0 |
| GHSA-v3r7-h72x-cjcm | undici@6.27.0 | 6.28.0 |
| GHSA-m8rv-5g2x-5cg5 | undici@6.27.0 | 6.28.0 |
| GHSA-r292-9mhp-454m | tar@7.5.19 | 7.5.21 |

### License violations

License violations (1)

| Package | License |
|---|---|
| awf-cli-proxy@1.0.0 | no licenses found |

### Next actions

- Update the Go toolchain/stdlib to 1.26.6+ (or 1.27.0-rc.3) to close all `GO-2026-*` stdlib findings — this is the single highest-impact fix for this image (7 of 9 High findings).
- Bump `brace-expansion`, `ip-address`, `undici`, and `tar` to the fixed versions listed above.
- `busybox`/`ssl_client`/`nghttp2-libs` fixes are pending upstream Alpine advisories; track and rebuild once patched packages are published.
- `awf-cli-proxy@1.0.0` has no declared license metadata — add a `license` field to its `package.json`.
- This image is rebuilt weekly via the daily `gh aw compile --force-refresh-container-pins` job; a pin-refresh PR is the default remediation path.

> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/31929401072) · auto · 438.5 AIC · ⌖ 15.1 AIC · ⊞ 7.2K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.