githubnext / githubnext/gh-aw-cao
[aw-doctor:compiler-security] Compiler & security scan findings: 45 workflows, 5 finding categories (exit code 1)
- Dominant language
- JavaScript
- Stars
- 3
- Forks
- 1
- Avg merge
- 49m
- Merged PRs (30d)
- 837
Description
gh-aw compiled all 45 workflow sources in `githubnext/gh-aw-cao` (45 lock files generated) but the full validation/lint/security suite exited **1**. Findings span 5 categories: 2 actionlint expression errors, 41 zizmor High `github-app` findings, 1 poutine Medium finding, 1883 grype container-vulnerability lines (20 Critical/160 High/765 Medium/81 Unknown across 9 images), and 1250 grant license-policy violations (mostly ISC/MIT/Apache-2.0 in container images). Highest severity: **Critical** (grype CVEs, e.g. CVE-2026-63073/CVE-2026-75803 in `squid`/`gh-aw-mcpg` images, and multiple `openssl`/`libssl3`/`libcrypto3` packages). No fix is possible for container-CVE/license findings from workflow sources — the images are pulled from upstream `ghcr.io/github/gh-aw-*` and public base images; only the actionlint/zizmor findings are addressable in `.github/workflows/*.md`.
**Action:** Assign this issue to Copilot using **Agent prompt** below; review its pull request and merge only after the full compiler and security scan passes.
Failure details
- **Target repository**: `githubnext/gh-aw-cao`
- **Compiler exit code**: `1`
- **Workflow sources checked**: `45`
- **Generated lock files checked**: `45`
- **Result**: `findings`
| Tool | Workflow / Image | Severity | Finding | Remediation |
|---|---|---|---|---|
| actionlint | `self-care-dashboard-performance.lock.yml`, `self-care-pages-health.lock.yml` | error | `safe-outputs-app-token` property not defined in expression context object | Fix the `.md` source expression referencing `safe-outputs-app-token`; recompile until actionlint is clean |
| zizmor | 41 lock files (e.g. `aw-doctor`, `dependabot`, `optimization*`, `self-care*`, `eu-cra-compliance*`, `uk-ai-advisory*`) | High | `github-app`: dangerous use of GitHub App tokens ((docs.zizmor.sh/redacted) | Review each workflow's GitHub App token generation/usage step; scope token permissions minimally and avoid unsafe exposure per zizmor guidance |
| poutine | `.github/workflows/agentic_commands.yml` | Medium | RGS-005 Excessive Permissions on Untrusted Trigger — write permissions combined with an externally-triggerable event | Reduce job permissions to read-only where the trigger accepts external input, or restrict the trigger |
| grype | `ghcr.io/github/gh-aw-firewall/squid:0.28.14` | Critical | CVE-2026-63073/CVE-2026-75803 in `libcrypto3`/`libssl3`/`openssl` (fix: 3.5.8-r0) | Upstream image update required (gh-aw firewall image); not fixable from workflow `.md` sources |
| grype | `ghcr.io/github/gh-aw-mcpg:v0.4.18` | Critical/High | CVE-2026-63073, GO-2026-5026/5037/5972/6090 in Go stdlib | Upstream image update required |
| grype | `ghcr.io/github/gh-aw-firewall/agent\|api-proxy\|cli-proxy:0.28.14` | High | GHSA-rgw5-rvv9-x895, GHSA-mh99-v99m-4gvg (`brace-expansion`), GHSA-r292-9mhp-454m (`tar`), GHSA-mwp4-54f8-5fhr (`ip-address`) | Upstream image update required |
| grype | `alpine:latest`, `node:lts-alpine`, `github-mcp-server:v1.11.0` | High/Critical/Medium | 18/22/8 findings respectively (see raw evidence) | Upstream base-image updates required |
| grant | 9 container images | policy | 1250 license-policy violations, dominated by ISC (365), MIT (285), Apache-2.0 (69), GPL-2.0-only (62) | Confirm license policy allow-list in `.poutine.yml`/grant config matches actual repo license posture; not fixable in workflow sources |
Agent prompt
1. Assign this issue to Copilot.
2. Configure its MCP client to launch `gh aw mcp-server` over stdio from the target repository, then give it the prompt below. Require the server's `fix` and `compile` tools; never allow direct edits to generated `.lock.yml` files.
3. Review the resulting pull request and require the same full compiler and security scan to pass before merge. If a finding needs human action, require the agent to stop and explain it.
**Agent prompt**
Fix the reported gh-aw compiler and security findings in this repository. Change only `.github/workflows/*.md` sources and directly related files; never edit generated `.lock.yml` files. Use the gh-aw MCP server's `fix` and `compile` tools, rerunning compilation with strict validation, model checks, actionlint, shellcheck, yamllint, zizmor, poutine, runner-guard, grant, grype, and syft until clean. Review generated lock-file diffs, preserve existing behavior, and stop with a concise explanation if a finding cannot be fixed safely. Note: container-image CVE and license-policy findings originate from upstream `ghcr.io/github/gh-aw-*` and public base images and cannot be resolved by editing workflow sources — flag those as out of scope and explain why.
Raw evidence
- Deterministic evidence stored at `/tmp/gh-aw/agent/aw-maintenance-compiler-security/` on the runner (report.txt: 9270 lines, 677KB; summary.txt; exit-code.txt; git-status.txt; result.json).
- `git-status.txt` shows only an untracked `.poutine.yml` (scanner config artifact, not a source change).
- Actionlint: 2 issues found (both `[expression]` category), 45 files checked.
- Zizmor: 45 files scanned, 41 High `github-app` findings, all identical rule ID across distinct workflows.
- Syft: 9 container images scanned successfully (567/193/347/63/288/177/41/16/165 packages respectively).
- Grype: 9 images scanned; totals by severity across all images: 20 Critical, 160 High, 765 Medium, 81 Unknown/Low.
- Grant: "strict mode: grant found 1250 license policy finding(s) in container images" — command reported failure due to policy violations, not a scanner malfunction.
- No token-like or credential-like values were present in the extracted report excerpts.
Control plane context
- Correlation ID: `34188154900-83`
- Central repository: `githubnext/gh-aw-cao`
- Control plane run URL: `https://github.com/githubnext/gh-aw-cao/actions/runs/34188154900`
> Generated by [:shield: AW Doctor / Compiler Security](https://github.com/githubnext/gh-aw-cao/actions/runs/34188392565) · copilot · auto · 39.6 AIC · ⌖ 12.6 AIC · ⊞ 14.2K · [◷](https://github.com/search?q=repo%3Agithubnext%2Fgh-aw-cao+is%3Aissue+%22gh-aw-workflow-call-id%3A+githubnext%2Fgh-aw-cao%2Faw-maintenance-compiler-security%22&type=issues)
> - [x] expires on Sep 22, 2026, 5:09 AM UTC
Contributor guide
Research direction
Start with the workflow sources under `.github/workflows/*.md`, especially the sources for `self-care-dashboard-performance`, `self-care-pages-health`, and `.github/workflows/agentic_commands.yml`; review the corresponding compiler findings and the zizmor guidance. Use the gh-aw MCP `fix` and `compile` tools, then rerun the named validation scanners. Done means addressable actionlint, zizmor, and poutine findings are resolved, generated lock-file changes are reviewed, and upstream image findings are clearly reported as out of scope.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions, markdown
- Domain
- ci-cd, devops, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100