[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.1
- Dominant language
- Go
- Stars
- 5.1k
- Forks
- 541
- Avg merge
- 5h 48m
- Merged PRs (30d)
- 773
Description
### Overview
Daily container scan findings for `ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.1` (pinned `sha256:f931e5e1e13f765605d03ef9511fc755d779a51b76581ea14586e9871506a610`).
### Key metrics
| Severity | Count |
|---|---|
| Critical | 0 |
| High | 9 |
| Medium | 12 |
| Low | 0 |
| Negligible | 0 |
| Unknown | 0 |
| License violations | 1 |
### Vulnerabilities
High (9)
| CVE/GHSA | Package | Fixed version |
|---|---|---|
| GO-2026-5026 | stdlib@go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
| GHSA-rgw5-rvv9-x895 | brace-expansion@5.0.7 | 5.0.9 |
| GO-2026-5942 | stdlib@go1.26.5 | 1.26.6, 1.27.0-rc.3 |
| GHSA-mh99-v99m-4gvg | brace-expansion@5.0.7 | 5.0.8 |
| GHSA-mwp4-54f8-5fhr | ip-address@10.2.0 | 10.3.1 |
| GO-2026-6089 | stdlib@go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
| GO-2026-6088 | stdlib@go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
| GO-2026-6090 | stdlib@go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
| GO-2026-5972 | stdlib@go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
Medium (12)
| CVE/GHSA | Package | Fixed version |
|---|---|---|
| CVE-2025-60876 | busybox@1.37.0-r31 | none published |
| CVE-2025-60876 | busybox-binsh@1.37.0-r31 | none published |
| CVE-2025-60876 | ssl_client@1.37.0-r31 | none published |
| GHSA-4xrf-jv44-h6hh | ip-address@10.2.0 | 10.2.2 |
| GHSA-22jq-vg5j-6vgg | ip-address@10.2.0 | 10.2.1 |
| CVE-2026-58055 | nghttp2-libs@1.69.0-r0 | none published |
| GO-2026-6091 | stdlib@go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
| GO-2026-6218 | stdlib@go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
| GHSA-8xcm-r25x-g524 | undici@6.27.0 | 6.28.0 |
| GHSA-v3r7-h72x-cjcm | undici@6.27.0 | 6.28.0 |
| GHSA-m8rv-5g2x-5cg5 | undici@6.27.0 | 6.28.0 |
| GHSA-r292-9mhp-454m | tar@7.5.19 | 7.5.21 |
### License violations
License violations (1)
| Package | License |
|---|---|
| awf-cli-proxy@1.0.0 | no licenses found |
### Next actions
- Update the Go toolchain/stdlib to 1.26.6+ (or 1.27.0-rc.3) to close all `GO-2026-*` stdlib findings — this is the single highest-impact fix for this image (7 of 9 High findings).
- Bump `brace-expansion`, `ip-address`, `undici`, and `tar` to the fixed versions listed above.
- `busybox`/`ssl_client`/`nghttp2-libs` fixes are pending upstream Alpine advisories; track and rebuild once patched packages are published.
- `awf-cli-proxy@1.0.0` has no declared license metadata — add a `license` field to its `package.json`.
- This image is rebuilt weekly via the daily `gh aw compile --force-refresh-container-pins` job; a pin-refresh PR is the default remediation path.
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/31929401072) · auto · 438.5 AIC · ⌖ 15.1 AIC · ⊞ 7.2K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
Contributor guide
Assessment
This issue has not been assessed yet.