githubnext / githubnext/gh-aw-cao

[aw-doctor:compiler-security] Compiler and security scan findings in githubnext/gh-aw-cao (exit 1: actionlint, zizmor, grype, grant)

Closed
#6,204 0 comments 0 reactions 0 assignees View on GitHub
aw-doctor aw-doctor:compiler-security
Dominant language
JavaScript
Stars
3
Forks
1
Avg merge
49m
Merged PRs (30d)
837

Description

Compiler for `githubnext/gh-aw-cao` exited with code 1 across 47 workflow sources / 47 lock files. Findings: 2 actionlint expression errors, 45 zizmor "github-app: dangerous use of GitHub App tokens" (High) findings plus 20 Critical / 164 High / 786 Medium container-image CVEs (grype), 1 poutine/runner-guard Medium excessive-permissions finding, and a grant license-policy failure (1250 findings across 9 container base images: alpine, node:lts-alpine, gh-aw-firewall/*, gh-aw-mcpg, gh-aw-node, github-mcp-server). Highest severity supported by tooling: **Critical** (grype CVE-2026-63073/CVE-2026-75803 in libssl3/libcrypto3, present in alpine, node:lts-alpine, gh-aw-firewall/squid, gh-aw-mcpg, github-mcp-server base images). Recommended next action: assign remediation to Copilot per the agent prompt below; the compiler+scanner suite must pass clean before merge.

**Action:** Assign this issue to Copilot using **Agent prompt** below; review its pull request and merge only after the full compiler and security scan passes.

Failure details

- **Target repository**: `githubnext/gh-aw-cao`
- **Compiler exit code**: `1`
- **Workflow sources checked**: `47`
- **Generated lock files checked**: `47`
- **Result**: `findings`

| Tool | Workflow / Image | Severity | Finding | Remediation |
|---|---|---|---|---|
| actionlint | `self-care-dashboard-performance.lock.yml`, `self-care-pages-health.lock.yml` | error | `safe-outputs-app-token` property not defined in referenced job-output object type (expression check) | Fix upstream expression/property reference in the `.md` source that generates these lock files; recompile |
| zizmor | 15 workflow lock files incl. `aw-doctor`, `aw-failures-investigator`, `aw-maintenance-compiler-security`, `dependabot*`, `eu-cra-compliance*`, `optimization*` (45 occurrences total) | High | `github-app`: dangerous use of GitHub App tokens | Review GitHub App token usage per (docs.zizmor.sh/redacted) scope/guard token exposure |
| zizmor | multiple workflow lock files | Medium (786), Low (354), Informational (288), Unknown (81) | undocumented-permissions, secrets-outside-env, anonymous-definition, adhoc-packages, etc. | Add permission comments, move secrets into dedicated environments, name workflow/action defs |
| poutine / runner-guard | `.github/workflows/agentic_commands.yml` | Medium | RGS-005 Excessive Permissions on Untrusted Trigger — write-level `permissions:` combined with `pull_request_target`/`issue_comment`-class trigger | Reduce permissions to read-only or gate write scope behind a separate, trusted job |
| grype (via zizmor CVE overlay) | `alpine:latest`, `node:lts-alpine`, `ghcr.io/github/gh-aw-firewall/squid:0.28.14`, `ghcr.io/github/gh-aw-mcpg:v0.4.18`, `ghcr.io/github/github-mcp-server:v1.11.0` | Critical (20) | CVE-2026-63073, CVE-2026-75803 (libssl3/libcrypto3), CVE-2026-5450 (libc6) | Bump base images to patched libssl3/libcrypto3 (3.5.8-r0+) and update `github-mcp-server` base past `libc6` fix |
| grype | 9 scanned container images (`gh-aw-firewall/*`, `gh-aw-mcpg`, `gh-aw-node`, `github-mcp-server`, `alpine`, `node:lts-alpine`) | High (164) | Numerous CVEs across libssl3/libcrypto3, brace-expansion, tar, ip-address, grpc, Go stdlib, x/crypto, x/text, docker-cli, libblkid/libmount | Update pinned image digests/tags to latest patched releases for each affected package |
| grant | 9 container images | Medium | 1250 license-policy violations (e.g. `HPND-sell-variant`, `MIT`, `ISC`, `GPL-*`, `BSD-*` combos flagged by strict policy) | Review `grant` license allow/deny policy vs. actual base-image license set; either adjust policy or swap flagged packages/images |

Agent prompt

1. Assign this issue to Copilot.
2. Configure its MCP client to launch `gh aw mcp-server` over stdio from the target repository, then give it the prompt below. Require the server's `fix` and `compile` tools; never allow direct edits to generated `.lock.yml` files.
3. Review the resulting pull request and require the same full compiler and security scan to pass before merge. If a finding needs human action, require the agent to stop and explain it.

**Agent prompt**

Fix the reported gh-aw compiler and security findings in this repository. Change only `.github/workflows/*.md` sources and directly related files; never edit generated `.lock.yml` files. Use the gh-aw MCP server's `fix` and `compile` tools, rerunning compilation with strict validation, model checks, actionlint, shellcheck, yamllint, zizmor, poutine, runner-guard, grant, grype, and syft until clean. Review generated lock-file diffs, preserve existing behavior, and stop with a concise explanation if a finding cannot be fixed safely.

Raw evidence

Compiler summary:
```
Target: githubnext/gh-aw-cao
Exit code: 1
Workflow sources: 47
Compiled locks: 47
```

Actionlint: 2 errors (expression category) — see failure table above for locations.

Zizmor severity totals: Critical 20, High 164, Medium 786, Low 354, Informational 288, Unknown 81 (across CVE and workflow-audit findings combined in the report).

Grant: `strict mode: grant found 1250 license policy finding(s) in container images` — scan failed (`✗ grant failed`).

Git status during scan showed one untracked file: `.poutine.yml` (present in the workspace but not committed; not itself a finding).

Full per-line detail (696KB) is retained in workflow run artifacts and was not reproduced in full here to keep this report bounded; the table above deduplicates and summarizes all distinct finding categories.

Control plane context

- Correlation ID: `34252923210-95`
- Central repository: `githubnext/gh-aw-cao`
- Control plane run URL: `https://github.com/githubnext/gh-aw-cao/actions/runs/34252923210`

> Generated by [:shield: AW Doctor / Compiler Security](https://github.com/githubnext/gh-aw-cao/actions/runs/34253385832) · copilot · auto · 43.5 AIC · ⌖ 11.9 AIC · ⊞ 14.2K · [◷](https://github.com/search?q=repo%3Agithubnext%2Fgh-aw-cao+is%3Aissue+%22gh-aw-workflow-call-id%3A+githubnext%2Fgh-aw-cao%2Faw-maintenance-compiler-security%22&type=issues)
> - [x] expires on Sep 22, 2026, 5:07 PM UTC

Contributor guide

Open the contributing guide

Research direction

Start with the .github/workflows/*.md sources that generate self-care-dashboard-performance.lock.yml and self-care-pages-health.lock.yml, plus .github/workflows/agentic_commands.yml. Use the gh-aw MCP server's fix and compile tools, then review generated lock-file diffs and rerun the full compiler and security scan. Done means the compiler, actionlint, zizmor, poutine, runner-guard, grant, grype, and related checks pass cleanly without editing generated .lock.yml files.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, github-actions, javascript
Domain
build-system, ci-cd, devops, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.