githubnext / githubnext/gh-aw-cao
[cao-evolution:compiler-security] Compiler + security scan findings: gh-aw-cao (34 High zizmor, 34 Critical/221 High CVEs, license policy failure)
- Dominant language
- JavaScript
- Stars
- 3
- Forks
- 1
- Avg merge
- 49m
- Merged PRs (30d)
- 837
Description
Compiling all 50 GitHub Agentic Workflows in `githubnext/gh-aw-cao` completed with **exit code 1**. The compiler, actionlint/shellcheck, zizmor, poutine, runner-guard, syft/grype (vulnerability), and grant (license) suite reports findings in 5 categories: actionlint (2 expression errors, 72 shellcheck notes), zizmor (High "github-app" token misuse in 34 workflow locks, Medium "artipacked"/"secrets-outside-env", Low/Informational rules), container vulnerabilities (grype: 34 Critical, 221 High CVEs across 8 base images), and container license policy violations (grant: 1250 findings, causing `grant failed`). Poutine and runner-guard reported no findings. Highest severity: **Critical CVEs** in `alpine:latest`, `ghcr.io/github/gh-aw-firewall/*`, `ghcr.io/github/gh-aw-mcpg`, `ghcr.io/github/gh-aw-node`, `ghcr.io/github/github-mcp-server`, and `node:lts-alpine` (e.g. CVE-2026-63073, CVE-2026-75803, CVE-2026-19931, CVE-2026-18924, CVE-2026-5450).
**Action:** Assign this issue to Copilot using **Agent prompt** below; review its pull request and merge only after the full compiler and security scan passes.
Failure details
- **Target repository**: `githubnext/gh-aw-cao`
- **Compiler exit code**: `1`
- **Workflow sources checked**: `50`
- **Generated lock files checked**: `50`
- **Result**: `findings`
| Tool | Workflow / Image | Severity | Finding | Remediation |
|---|---|---|---|---|
| actionlint (expression) | `self-care-dashboard-performance.lock.yml`, `self-care-pages-health.lock.yml` | High | `safe-outputs-app-token` not defined in step-outputs object type | Fix property reference / conditional in the workflow's compiled expression source |
| actionlint (shellcheck SC1003) | 18 lock files (e.g. `dashboard-authoring-corpus.lock.yml:866`, `eu-cra-compliance*.lock.yml`) | Low/info | Unescaped single quote in "Pi CLI" example string (`echo 'This is how it's done'`) | Escape the embedded quote in the shared script/prompt source that generates this step |
| actionlint (shellcheck SC2034) | ~14 `graders/*-operational-value.sh` scripts | Low | Unused variables (`WORKFLOW_NAME`, `SOURCE_PATH`, etc.) | Export or remove unused grader script variables |
| zizmor | 34 workflow lock files (e.g. `cao-evolution.lock.yml:1722`, `optimization.lock.yml:1665`) | High | `github-app`: dangerous use of GitHub App tokens | Review token scoping per zizmor's github-app audit guidance |
| zizmor | 17 workflow lock files | Medium | `artipacked`: credential persistence through GitHub Actions artifacts | Avoid persisting credentials in uploaded artifacts |
| zizmor | most workflow lock files (414 occurrences) | Medium | `secrets-outside-env`: secrets referenced without a dedicated `environment:` | Reference secrets via a job `environment:` block |
| grype | `alpine:latest`, `ghcr.io/github/gh-aw-firewall/api-proxy`, `.../cli-proxy`, `.../squid`, `ghcr.io/github/gh-aw-mcpg`, `ghcr.io/github/gh-aw-node`, `ghcr.io/github/github-mcp-server`, `node:lts-alpine` | Critical | e.g. CVE-2026-63073/CVE-2026-75803 (libcrypto3/libssl3 3.5.7-r0), CVE-2026-19931/CVE-2026-18924 (curl/libcurl 8.21.0-r0), CVE-2026-5450 (libc6 2.36-9+deb12u14) | Rebuild/pull updated base images (fixes available: e.g. libssl3 3.5.8-r0, libcurl 8.22.0-r0) |
| grype | Same images plus `ghcr.io/github/gh-aw-firewall/agent`, npm packages (`brace-expansion`, `tar`, `ip-address`, `undici`) | High (221 total) | Various CVEs with published fixes | Update base images and bundled npm dependencies to fixed versions |
| grant (license scanner) | `alpine:latest` and other images | Unknown (policy violation) | 1250 license policy violations (e.g. GPL-2.0-only packages in `alpine:latest`) causing `grant failed` | Review license allow-list policy or swap disallowed-license base packages |
| poutine | n/a | — | No findings | None |
| runner-guard | n/a | — | No findings | None |
Agent prompt
1. Assign this issue to Copilot.
2. Configure its MCP client to launch `gh aw mcp-server` over stdio from the target repository, then give it the prompt below. Require the server's `fix` and `compile` tools; never allow direct edits to generated `.lock.yml` files.
3. Review the resulting pull request and require the same full compiler and security scan to pass before merge. If a finding needs human action, require the agent to stop and explain it.
**Agent prompt**
Fix the reported gh-aw compiler and security findings in this repository. Change only `.github/workflows/*.md` sources and directly related files; never edit generated `.lock.yml` files. Use the gh-aw MCP server's `fix` and `compile` tools, rerunning compilation with strict validation, model checks, actionlint, shellcheck, yamllint, zizmor, poutine, runner-guard, grant, grype, and syft until clean. Review generated lock-file diffs, preserve existing behavior, and stop with a concise explanation if a finding cannot be fixed safely.
Raw evidence
- Exit code: `1`
- `git-status.txt`: `?? .poutine.yml` (untracked scanner config, no other repo mutations)
- Issue counts (actionlint summary): 74 issues (2 expression, 72 shellcheck)
- zizmor rule counts: github-app High=49 (34 unique files), artipacked Medium=31, secrets-outside-env Medium=414, anonymous-definition Informational=297, undocumented-permissions Low=292, template-injection Informational=9, adhoc-packages Low=25, obfuscation Low=3
- grype severity counts: Critical=34, High=221, Medium=758, Low=374, Negligible=27, Unknown=18
- grant: `grant failed — strict mode: grant found 1250 license policy finding(s) in container images`
- Full raw report is 10,383 lines; only representative/aggregated findings are included above. No token-like or credential-like values were present in the excerpted output.
Control plane context
- Correlation ID: `34757506669-57`
- Central repository: `githubnext/gh-aw-cao`
- Control plane run URL: `https://github.com/githubnext/gh-aw-cao/actions/runs/34757506669`
> Generated by [:shield: CAO Evolution / AW Compiler Security](https://github.com/githubnext/gh-aw-cao/actions/runs/34757776411) · copilot · auto · 48.8 AIC · ⌖ 8.73 AIC · ⊞ 12.6K · [◷](https://github.com/search?q=repo%3Agithubnext%2Fgh-aw-cao+is%3Aissue+%22gh-aw-workflow-call-id%3A+githubnext%2Fgh-aw-cao%2Fcao-evolution-compiler-security%22&type=issues)
> - [x] expires on Sep 27, 2026, 12:59 PM UTC
Contributor guide
Research direction
Start in .github/workflows/*.md and configure the gh aw MCP server from the target repository. Run the compiler and its strict validation, then review findings from actionlint, shellcheck, zizmor, grant, grype, syft, poutine, and runner-guard without editing generated .lock.yml files. Done means the full compiler and security scan passes, or an unsafe unresolved finding is clearly explained.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker, github-actions, javascript
- Domain
- ci-cd, devops, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100