[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/squid:0.28.1
- Dominant language
- Go
- Stars
- 5.1k
- Forks
- 541
- Avg merge
- 5h 48m
- Merged PRs (30d)
- 773
Description
### Overview
Daily container scan findings for `ghcr.io/github/gh-aw-firewall/squid:0.28.1` (pinned `sha256:9d428af47899bf18ef2d5618075777d76ef344c91e76c1f44ec1aaa0ee347e5f`).
### Key metrics
| Severity | Count |
|---|---|
| Critical | 0 |
| High | 0 |
| Medium | 4 |
| Low | 0 |
| Negligible | 0 |
| Unknown | 0 |
| License violations | 11 |
### Vulnerabilities
Medium (4)
| CVE/GHSA | Package | Fixed version |
|---|---|---|
| CVE-2025-60876 | busybox@1.37.0-r31 | none published |
| CVE-2025-60876 | busybox-binsh@1.37.0-r31 | none published |
| CVE-2025-60876 | ssl_client@1.37.0-r31 | none published |
| CVE-2026-58055 | nghttp2-libs@1.69.0-r0 | none published |
### License violations
License violations (11)
| Package | License |
|---|---|
| acl-libs@2.3.2-r1 | GPL-2.0-or-later, LGPL-2.1-or-later |
| libcom_err@1.47.4-r0 | GPL-2.0-or-later, LGPL-2.0-or-later |
| bind-libs@9.20.26-r0 | MPL-2.0 |
| logrotate@3.22.0-r0 | GPL-2.0-or-later |
| squid@7.6-r0 | GPL-2.0-or-later |
| userspace-rcu@0.15.3-r0 | LGPL-2.1-or-later |
| xz-libs@5.8.3-r0 | 0BSD, AND, GPL-2.0-or-later, LGPL-2.1-or-later, Public-Domain |
| bind-tools@9.20.26-r0 | MPL-2.0 |
| keyutils-libs@1.6.3-r4 | GPL-2.0-or-later, LGPL-2.0-or-later |
| mii-tool@2.10-r3 | GPL-2.0-or-later |
| libltdl@2.6.0-r1 | LGPL-2.0-or-later, GPL-2.0-or-later |
### Next actions
- No High/Critical CVEs in this image; the 4 Medium findings are all pending upstream Alpine advisories (`busybox`, `ssl_client`, `nghttp2-libs`) — track and rebuild once patched packages are published.
- All 11 license findings are copyleft (GPL/LGPL/MPL) licenses on base OS packages already permitted by the squid/Alpine distribution; confirm these are covered by the project's existing license allowlist/exception policy, or add explicit exceptions if the policy should reject copyleft licenses in this image.
- This image is rebuilt weekly via the daily `gh aw compile --force-refresh-container-pins` job.
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/31929401072) · auto · 438.5 AIC · ⌖ 15.1 AIC · ⊞ 7.2K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
Contributor guide
Assessment
This issue has not been assessed yet.