github / github/gh-aw

[container-image-scan] Test file body

Open
#54,745 1 comment 0 reactions 1 assignee Claimed by @pelikhan View on GitHub
cookie security
Dominant language
Go
Stars
5.1k
Forks
541
Avg merge
5h 46m
Merged PRs (30d)
760

Description

### ⚠️ Operational note

During this run, an `update_issue` test call accidentally consumed this workflow's single `update_issue` quota with placeholder text (`"test body"`), which overwrote the body of #52657 ("Container CVE burn-down") before the real report could be submitted. **#52657's body currently shows placeholder text and needs to be manually restored** using the full report below (or via a follow-up `gh aw` run).

The correct, complete report content that should replace #52657's body is included below in full, unmodified.

---

### Overview

Daily scan of 10 container images (Syft SBOM + Grype vulnerabilities + Grant license policy). Compiled with `gh aw compile --force-refresh-container-pins`. Run: https://github.com/github/gh-aw/actions/runs/32554786176

Only one image (`ghcr.io/github/gh-aw-node`) is **vendored** (built from `/Dockerfile` in this repo); every other image is **upstream** (owned by `github/gh-aw-firewall`, `github/gh-aw-mcpg`, `github/github-mcp-server`, `oraios/serena`, Docker Official `node`, or `grafana/mcp-grafana`).

### Summary table (Critical → High → Medium → Low → Unknown)

| Image | Pinned ref | Class | Critical | High | Medium | Low | Unknown |
|---|---|---|---|---|---|---|---|
| ghcr.io/oraios/serena | latest@sha256:aa8acaa... | Upstream (oraios/serena) | 50 | 127 | 154 | 32 | 39 |
| node | lts-alpine@sha256:d32cdf6... | Upstream (Docker Official node) | 1 | 8 | 12 | 2 | 0 |
| ghcr.io/github/gh-aw-mcpg | v0.4.10@sha256:08bb5fa... | Upstream (github/gh-aw-mcpg) | 0 | 22 | 14 | 7 | 1 |
| ghcr.io/github/github-mcp-server | v1.10.0@sha256:097512d... | Upstream (github/github-mcp-server, 3rd-party build) | 0 | 1 | 3 | 1 | 1 |
| ghcr.io/github/gh-aw-firewall/agent | 0.28.4@sha256:8f18587... | Upstream (github/gh-aw-firewall) | 0 | 3 | 260 | 62 | 0 |
| ghcr.io/github/gh-aw-firewall/api-proxy | 0.28.4@sha256:64e6682... | Upstream (github/gh-aw-firewall) | 0 | 5 | 11 | 0 | 0 |
| ghcr.io/github/gh-aw-firewall/cli-proxy | 0.28.4@sha256:7ad9113... | Upstream (github/gh-aw-firewall) | 0 | 5 | 10 | 0 | 0 |
| ghcr.io/github/gh-aw-firewall/squid | 0.28.4@sha256:35953d0... | Upstream (github/gh-aw-firewall) | 0 | 3 | 4 | 0 | 0 |
| ghcr.io/github/gh-aw-node | sha256:bac2192... (vendored build, refreshed this run) | **Vendored** (built from `/Dockerfile` in this repo) | 0 | 2 | 4 | 0 | 0 |
| grafana/mcp-grafana | 1.1.0-alpine@sha256:e0eb29c... | Upstream (Grafana Labs, 3rd party) | 0 | 2 | 0 | 0 | 0 |

**Totals: 51 Critical, 178 High findings across 10 scanned images.** (Raw vuln rows include duplicate CVEs across packages within the same image; per-image detail below de-duplicates by CVE/GHSA ID.)

### Per-image detail

ghcr.io/oraios/serena — Upstream — 50 Critical, 127 High, 154 Medium, 32 Low, 39 Unknown

Classification: **Upstream — tracked only**. Owned by `oraios/serena` (third party, Debian trixie + Node.js + npm/pip deps). No code fix can land in `github/gh-aw`.

**Critical (de-duplicated by CVE):**
- CVE-2025-55130 — node@22.18.0 (fix: 20.20.0/22.22.0/24.13.0/25.3.0)
- CVE-2026-11856, CVE-2026-9079, CVE-2026-8924, CVE-2026-10536, CVE-2026-8927, CVE-2026-8926 — curl/libcurl3t64-gnutls/libcurl4t64@8.14.1-2+deb13u4 (no fix yet)
- CVE-2026-5450 — libc-bin/libc-dev-bin/libc6/libc6-dev@2.41-12+deb13u3 (glibc, no fix yet)
- CVE-2026-8376, CVE-2026-13221, CVE-2026-42496, CVE-2026-12087, CVE-2026-57433 — libperl5.40/perl/perl-base/perl-modules-5.40@5.40.1-6 (no fix yet)
- CVE-2026-60002 — openssh-client/server/sftp-server, ssh@1:10.0p1-7+deb13u4 (no fix yet)
- GHSA-23hp-3jrh-7fpw — tar@6.2.1/7.4.3 (fix: 7.5.19, npm-bundled tar)

**High (de-duplicated):**
- GHSA-5j98-mcp5-4vw2 — glob@10.4.5 (fix: 10.5.0)
- GHSA-34x7-hfp2-rc4v, GHSA-8x88-c5mf-7j5w, GHSA-qffp-2rhf-9h96, GHSA-8qq5-rm4j-mr97, GHSA-83g3-92jg-28cx, GHSA-9ppj-qmqm-q256, GHSA-r6q2-hw4h-h46w — tar@6.2.1/7.4.3 (fix: 7.5.3–7.5.18, multiple advisories)
- GHSA-rgw5-rvv9-x895, GHSA-mh99-v99m-4gvg, GHSA-3jxr-9vmj-r5cp — brace-expansion@2.0.2 (fix: 2.1.2–2.1.4)
- GHSA-3ppc-4f35-3m26, GHSA-7r86-cg39-jmmj, GHSA-23c5-xmqv-rm74 — minimatch@9.0.5 (fix: 9.0.6/9.0.7)
- GHSA-c2c7-rcm5-vvqj — picomatch@4.0.2 (fix: 4.0.4)
- GHSA-mwp4-54f8-5fhr — ip-address@9.0.5 (fix: 10.3.1)
- GHSA-52v5-jr5w-gjxr — sigstore@3.1.0 (fix: 4.1.1)
- GHSA-8rrh-rw8j-w5fx — wheel@0.45.1 (fix: 0.46.2)
- GHSA-58pv-8j8x-9vj2 — jaraco-context@5.3.0 (fix: 6.1.0)
- CVE-2026-21710, CVE-2025-59465, CVE-2025-55131, CVE-2026-21637, CVE-2025-59466, CVE-2026-56846, CVE-2026-56848, CVE-2026-48617, CVE-2026-58043 — node@22.18.0 (fix: 20.20.0/22.22.0–22.23.2/24.13.0–24.18.1/25.3.0/26.5.1)
- CVE-2026-7210, CVE-2026-4224, CVE-2026-3644 — python@3.11.16 (fix: 3.13.x/3.14.x/3.15.0)
- CVE-2026-58050, CVE-2026-58051, CVE-2026-66032, CVE-2026-66033, CVE-2026-66034, CVE-2026-66035 — libssh2-1t64@1.11.1-1+deb13u1 (no fix yet)
- CVE-2026-14456 — libssl3t64/openssl/openssl-provider-legacy@3.5.6-1~deb13u2 (no fix yet)
- CVE-2025-69720 — libncursesw6/libtinfo6/ncurses-base/ncurses-bin@6.5+20250216-2 (no fix yet)
- CVE-2026-58469, CVE-2026-58471, CVE-2026-58472 — wget@1.25.0-2 (no fix yet)
- CVE-2026-41992 — gzip@1.13-1 (no fix yet)
- CVE-2026-11822, CVE-2026-11824 — libsqlite3-0@3.46.1-7+deb13u1 (no fix yet)
- CVE-2026-54369, CVE-2026-54370 — libacl1@2.3.2-2+b1 (no fix yet)
- CVE-2026-9538, CVE-2026-42497, CVE-2026-48959, CVE-2026-48961, CVE-2026-48962, CVE-2026-7017, CVE-2026-57432 — libperl5.40/perl/perl-base/perl-modules-5.40@5.40.1-6 (no fix yet)
- CVE-2026-60000, CVE-2026-59999 — openssh-client/server/sftp-server, ssh@1:10.0p1-7+deb13u4 (no fix yet)
- CVE-2026-9080, CVE-2026-8932 — curl/libcurl3t64-gnutls/libcurl4t64@8.14.1-2+deb13u4 (no fix yet)
- CVE-2026-5928, CVE-2026-5435 — libc-bin/libc-dev-bin/libc6/libc6-dev@2.41-12+deb13u3 (no fix yet)

**Medium (selected, de-duplicated CVE/package):** CVE-2021-31879 wget, CVE-2025-12781/CVE-2025-15366/CVE-2025-15367/CVE-2025-13837/CVE-2026-6019/CVE-2026-3446/CVE-2026-4360 python, CVE-2026-58042/58041/58040/58045/58044/58039/56847/56850 node, GHSA-f886-m6hf-6m8v brace-expansion, GHSA-v2v4-37r5-5v8g ip-address, GHSA-4xh5-x5gv-qwph/GHSA-wf93-45jw-7689/GHSA-jp4c-xjxw-mgf9/GHSA-58qw-9mgm-455v/GHSA-6vgw-5pg2-w6jp pip, GHSA-h35f-9h28-mq5c setuptools, CVE-2026-3184/CVE-2026-27456/CVE-2026-13595 util-linux family (bsdutils, libblkid1, liblastlog2-2, libmount1, libsmartcols1, libuuid1, login, mount), CVE-2026-19487/CVE-2026-7010/CVE-2026-15534/CVE-2025-15649 perl family, GHSA-3v7f-55p6-f55p picomatch, GHSA-w8wr-v893-vjvp/GHSA-gvwx-54wh-qm9j/GHSA-vmf3-w455-68vh/GHSA-r292-9mhp-454m tar, CVE-2026-6238/CVE-2026-6791 libc6 family, CVE-2026-54411 libpam, CVE-2026-5704/CVE-2026-18508/CVE-2026-18477 tar (Debian), CVE-2026-8458 curl, CVE-2026-60001/59996/59995/59998/59997/73282/55655 openssh, CVE-2026-76956/2025-66382/76957 libexpat1, GHSA-jfc7-64v2-mr8c ``@sigstore/core``, libnghttp2-14 CVE-2026-58055, CVE-2026-15146/58470 wget, CVE-2025-6141 ncurses family, CVE-2026-13757/18938 libp11-kit0, CVE-2026-50812/50813 libsqlite3-0, CVE-2026-54371 libattr1, CVE-2026-15059/16742 systemd family, CVE-2026-42250 bzip2.

**Low (32):** GHSA-73rr-hh4g-fpgx diff, CVE-2026-55654/73281/73283 openssh, CVE-2026-4519 python, CVE-2024-56433 login.defs/passwd, CVE-2026-48931/58044/58039/56847/21715/21716 node, GHSA-6vgw-5pg2-w6jp pip, CVE-2026-40228 systemd family, CVE-2025-13462 python, CVE-2026-6368 libc6 family.

**Unknown (39):** CVE-2026-53612/53613/53614/53615 — util-linux family (bsdutils, libblkid1, liblastlog2-2, libmount1, libsmartcols1, libuuid1, login, mount) — fix 2.41.5-0+deb13u1; CVE-2026-75803 — libssl3t64/openssl/openssl-provider-legacy@3.5.6-1~deb13u2 (no fix yet).

Remediation: Upstream — tracked only. Awaiting `oraios/serena` to rebuild `latest` on a refreshed Debian trixie/Node base. Daily pin-refresh picks up the new digest automatically once published. No advisory/issue link found yet in the `oraios/serena` tracker for these specific CVEs.

node:lts-alpine — Upstream — 1 Critical, 8 High, 12 Medium, 2 Low

Classification: **Upstream — tracked only** (Docker Official Images `node`, base for `ghcr.io/github/gh-aw-node`).

- [Critical] GHSA-23hp-3jrh-7fpw — tar@7.5.16 (fix: 7.5.19)
- [High] GHSA-8x88-c5mf-7j5w — tar@7.5.16 (fix: 7.5.18)
- [High] GHSA-rgw5-rvv9-x895 — brace-expansion@5.0.6 (fix: 5.0.9)
- [High] GHSA-mh99-v99m-4gvg — brace-expansion@5.0.6 (fix: 5.0.8)
- [High] GHSA-3jxr-9vmj-r5cp — brace-expansion@5.0.6 (fix: 5.0.7)
- [High] GHSA-mwp4-54f8-5fhr — ip-address@10.2.0 (fix: 10.3.1)
- [High] GHSA-vxpw-j846-p89q — undici@6.26.0 (fix: 6.27.0)
- [High] CVE-2026-14456 — libcrypto3/libssl3@3.5.7-r0 (no fix yet)
- [Medium] GHSA-w8wr-v893-vjvp/GHSA-gvwx-54wh-qm9j/GHSA-r292-9mhp-454m — tar@7.5.16 (fix: 7.5.17–7.5.21)
- [Medium] CVE-2025-60876 — busybox/busybox-binsh/ssl_client@1.37.0-r31 (no fix yet)
- [Medium] GHSA-4xrf-jv44-h6hh/GHSA-22jq-vg5j-6vgg — ip-address@10.2.0 (fix: 10.2.1/10.2.2)
- [Medium] GHSA-p88m-4jfj-68fv/GHSA-8xcm-r25x-g524/GHSA-v3r7-h72x-cjcm/GHSA-m8rv-5g2x-5cg5 — undici@6.26.0 (fix: 6.27.0/6.28.0)
- [Low] GHSA-g8m3-5g58-fq7m/GHSA-35p6-xmwp-9g52 — undici@6.26.0 (fix: 6.27.0)

Remediation: Upstream — tracked only. Packages inherited from the `node:lts-alpine` base used to build `ghcr.io/github/gh-aw-node` (vendored, see below). Daily pin-refresh already bumps `node:lts-alpine` as new patch tags publish; no local code fix applies to this base layer.

ghcr.io/github/gh-aw-node — Vendored — 0 Critical, 2 High, 4 Medium

Classification: **Vendored**. Built from `/Dockerfile` in `github/gh-aw`. Pin refreshed this run to `sha256:bac2192f6374d6262116399b34fc5e143d576f82719e90a18261cae7480f4d4e`.

- [High] CVE-2026-14456 — libcrypto3/libssl3@3.5.7-r0 (no fix yet, inherited from node:lts-alpine base)
- [Medium] CVE-2025-60876 — busybox/busybox-binsh/ssl_client@1.37.0-r31 (no fix yet)
- [Medium] CVE-2026-58055 — nghttp2-libs@1.69.0-r0 (no fix yet)

Remediation: All findings are inherited from the `node:lts-alpine` base layer, not from anything added in this repo's Dockerfile. Continue relying on the daily `--force-refresh-container-pins` refresh to pick up Alpine security updates as they land; no local Dockerfile change is required at this time. If `libcrypto3`/`libssl3` remain unfixed past 30 days (High SLA), consider pinning to a newer Alpine release explicitly here since this image IS vendored.

ghcr.io/github/gh-aw-mcpg — Upstream — 0 Critical, 22 High, 14 Medium, 7 Low, 1 Unknown

Classification: **Upstream — tracked only** (owned by `github/gh-aw-mcpg`).

**High:** GO-2026-5026, GO-2026-5037, GO-2026-6089, GO-2026-6090, GO-2026-5972, GO-2026-5942, GO-2026-4970 — Go stdlib@go1.26.3/go1.26.4 (fix: 1.25.11–1.25.13, 1.26.4–1.26.6, 1.27.0-rc.3); GO-2026-5970 — golang.org/x/text@v0.38.0 (fix: 0.39.0); GHSA-f5mr-q85p-6hh6 — github.com/sigstore/fulcio@v1.8.5 (fix: 1.8.6); GHSA-hfg8-hc9c-6c3h — github.com/moby/go-archive@v0.2.0 (fix: 0.3.0); GHSA-hrxh-6v49-42gf — google.golang.org/grpc@v1.81.1 (fix: 1.82.1); CVE-2026-14456 — libcrypto3/libssl3@3.5.7-r0 (no fix yet).

**Medium:** stdlib go1.26.3/go1.26.4 additional advisories (cl/803681, cl/775960, issue/79346, issue/80435); GHSA-7236-3392-c5c6 — github.com/moby/buildkit@v0.30.0 (fix: 0.31.1); CVE-2025-60876 busybox family; GHSA-xjvp-4fhw-gc47 — github.com/opencontainers/runc@v1.4.2 (fix: 1.4.3).

**Low:** GHSA-72x6-4j93-7w86 — github.com/moby/buildkit@v0.30.0 (fix: 0.31.1); CVE-2022-3219 — gnupg-dirmngr/gnupg-gpgconf/gnupg-keyboxd/gpg/gpg-agent/gpgsm@2.4.9-r1 (no fix yet).

**Unknown:** golang.org/x/crypto@v0.53.0 (issue/44226, no fix version listed).

Remediation: Upstream — tracked only. Requires `github/gh-aw-mcpg` to rebuild with a newer Go toolchain and bumped `x/text`, `fulcio`, `grpc`, `go-archive`, `buildkit`, `runc` module versions. Daily pin-refresh in this repo picks up a new `gh-aw-mcpg` release once published; no fix can land in `github/gh-aw`.

ghcr.io/github/github-mcp-server — Upstream — 0 Critical, 1 High, 3 Medium, 1 Low, 1 Unknown

Classification: **Upstream — tracked only** (owned by `github/github-mcp-server`, third-party build).

- [High] CVE-2026-14456 — libssl3@3.0.20-1~deb12u2 (Debian, no fix yet)
- [Medium] CVE-2026-42767 — libssl3@3.0.20-1~deb12u2 (no fix yet)
- [Medium] CVE-2026-6238, CVE-2026-6791 — libc6@2.36-9+deb12u14 (no fix yet)
- [Low] CVE-2026-6368 — libc6@2.36-9+deb12u14 (no fix yet)
- [Unknown] CVE-2026-75803 — libssl3@3.0.20-1~deb12u2 (no fix yet)

Remediation: Upstream — tracked only. Awaiting `github/github-mcp-server` to rebuild with an updated Debian base carrying patched OpenSSL/glibc. Pin-refresh will pick up the new release automatically.

ghcr.io/github/gh-aw-firewall/agent, api-proxy, cli-proxy, squid — Upstream — 0 Critical, 3–5 High each

Classification: **Upstream — tracked only** (owned by `github/gh-aw-firewall`).

Common High findings across `agent`, `api-proxy`, `cli-proxy`:
- GHSA-rgw5-rvv9-x895 — brace-expansion@5.0.7 (fix: 5.0.9)
- GHSA-mh99-v99m-4gvg — brace-expansion@5.0.7 (fix: 5.0.8)
- GHSA-mwp4-54f8-5fhr — ip-address@10.2.0 (fix: 10.3.1)

`api-proxy`/`cli-proxy` additionally: CVE-2026-14456 — libcrypto3/libssl3@3.5.7-r0 (no fix yet).

`squid` High: CVE-2026-14456 — libcrypto3/libssl3/openssl@3.5.7-r0 (no fix yet).

**Medium (all images, mostly shared):** CVE-2025-60876 busybox/busybox-binsh/ssl_client@1.37.0-r31, CVE-2026-58055 nghttp2-libs@1.69.0-r0; `api-proxy`/`cli-proxy` also: GHSA-8988-4f7v-96qf ``@opentelemetry/core`` ```@1```.30.1 (fix: 2.8.0), GHSA-4xrf-jv44-h6hh/GHSA-22jq-vg5j-6vgg ip-address, GHSA-8xcm-r25x-g524/GHSA-v3r7-h72x-cjcm/GHSA-m8rv-5g2x-5cg5 undici@6.27.0 (fix: 6.28.0), GHSA-r292-9mhp-454m tar@7.5.19 (fix: 7.5.21).

`agent` additionally carries **260 Medium / 62 Low** findings from its Ubuntu 22.04 base (bind9-libs, libpython3.10*, libperl5.34, curl/libcurl4, libpixman-1-0, libcairo2, libtiff5, libjpeg-turbo8, libzstd1, libgcrypt20, libpcre2, ncurses family, git, php8.1* — no Critical/High among these; full list omitted for brevity, all packages of the same shared Ubuntu base image).

**License policy violations (Grant), all on `squid`, `api-proxy`, `cli-proxy`:**
- `api-proxy`: `awf-api-proxy@1.0.0` (no licenses found — missing `license` field in package.json)
- `cli-proxy`: `awf-cli-proxy@1.0.0` (no licenses found — same root cause)
- `squid` (11 violations, copyleft/weak-copyleft on Alpine OS packages): `libltdl@2.6.0-r1` (LGPL-2.0-or-later, GPL-2.0-or-later), `bind-libs@9.20.26-r0` (MPL-2.0), `acl-libs@2.3.2-r1` (LGPL-2.1-or-later, GPL-2.0-or-later), `userspace-rcu@0.15.3-r0` (LGPL-2.1-or-later), `logrotate@3.22.0-r0` (GPL-2.0-or-later), `mii-tool@2.10-r3` (GPL-2.0-or-later), `squid@7.6-r0` (GPL-2.0-or-later), `bind-tools@9.20.26-r0` (MPL-2.0), `xz-libs@5.8.3-r0` (0BSD, AND, GPL-2.0-or-later, LGPL-2.1-or-later, Public-Domain), `libcom_err@1.47.4-r0` (GPL-2.0-or-later, LGPL-2.0-or-later), `keyutils-libs@1.6.3-r4` (GPL-2.0-or-later, LGPL-2.0-or-later)

Remediation: Upstream — tracked only. Requires `github/gh-aw-firewall` to bump `brace-expansion`/`ip-address`/`undici`/`@opentelemetry/core` npm packages, add missing `license` fields to `awf-api-proxy`/`awf-cli-proxy` package.json, and rebuild `agent`/`squid` on refreshed base images. Daily pin-refresh in this repo picks up new `gh-aw-firewall` releases automatically; no code fix can land here.

grafana/mcp-grafana — Upstream — 0 Critical, 2 High

Classification: **Upstream — tracked only** (Grafana Labs, third party).

- [High] CVE-2026-14456 — libcrypto3/libssl3@3.5.7-r0 (no fix yet)

Remediation: Upstream — tracked only. Awaiting Grafana Labs to rebuild `mcp-grafana` with a patched OpenSSL/Alpine base. Pin-refresh will pick this up automatically.

### Remediation SLA

- **Critical** findings are remediated or explicitly risk-accepted within **7 days**.
- **High** findings are remediated within **30 days**.
- Every scanned image is rebuilt on a refreshed base image **at least weekly** — this workflow runs `gh aw compile --force-refresh-container-pins` daily, so a pin-refresh PR is the default remediation step.
- For findings on **upstream** images (`oraios/serena`, `node:lts-alpine`, `gh-aw-mcpg`, `github-mcp-server`, `gh-aw-firewall/*`, `grafana/mcp-grafana`), no local code-fix PR is requested here — they are labeled **"Upstream — tracked only"** and remediated automatically via the daily pin-refresh once the owning repository publishes a patched release.
- The only **vendored** image is `ghcr.io/github/gh-aw-node`; all its findings currently trace to the `node:lts-alpine` base, not to anything added in this repo's Dockerfile.

### Next actions

- `oraios/serena` remains the dominant Critical/High source (50/127) — all upstream, tracked only, awaiting a new `latest` image build with patched Debian trixie/Node/curl/openssh/perl packages.
- `CVE-2026-14456` (libssl3/libcrypto3/openssl) recurs across 7 of 10 images (all Alpine/Debian-OpenSSL-based) — a single upstream OpenSSL patch release would clear most of this run's High findings once each base image rebuilds.
- No open `Container findings for ...` duplicate issues exist this run — nothing to close.
- Continue the daily pin-refresh cadence; re-evaluate `gh-aw-node`'s findings if they escalate beyond the inherited base-image Medium/High set.

> Generated by 🛡️ Daily Container Image Security Scan · Run: https://github.com/github/gh-aw/actions/runs/32554786176 (recovery issue — see note above regarding #52657)

> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/32554786176) · auto · 186.2 AIC · ⌖ 4.66 AIC · ⊞ 7.8K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.