Summary
Image: ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.44
- Vulnerabilities: 0 Critical / 4 High / 12 Medium / 2 Low / 0 Negligible
- License policy violations: 40
Vulnerabilities
High
GHSA-rgw5-rvv9-x895: brace-expansion@5.0.7 (fix: 5.0.9)
GHSA-mh99-v99m-4gvg: brace-expansion@5.0.7 (fix: 5.0.8)
GHSA-mwp4-54f8-5fhr: ip-address@10.2.0 (fix: 10.3.1)
CVE-2026-58043: node@22.23.1 (no fix version listed by Grype yet)
Medium (12) and Low (2)
GHSA-4xrf-jv44-h6hh: ip-address@10.2.0 (fix: 10.2.2)
GHSA-22jq-vg5j-6vgg: ip-address@10.2.0 (fix: 10.2.1)
CVE-2025-60876: busybox@1.37.0-r31, busybox-binsh@1.37.0-r31, ssl_client@1.37.0-r31 (no fix listed)
CVE-2026-58040: node@22.23.1 (fix: 22.23.2, 24.18.1, 26.5.1)
CVE-2026-58055: nghttp2-libs@1.69.0-r0 (no fix listed)
GHSA-v3r7-h72x-cjcm, GHSA-8xcm-r25x-g524, GHSA-m8rv-5g2x-5cg5: undici@6.27.0 (fix: 6.28.0)
CVE-2026-56850: node@22.23.1 (no fix listed)
GHSA-r292-9mhp-454m: tar@7.5.19 (fix: 7.5.21)
- Low:
CVE-2026-58039: node@22.23.1 (fix: 22.23.2); CVE-2026-56847: node@22.23.1 (no fix listed)
License Policy Violations
40 violations. Alpine base-layer GPL-2.0/LGPL/GPL-3.0 packages (busybox, apk-tools, alpine-baselayout, musl-utils, libgcc, libstdc++, libidn2, libunistring, zstd-libs, bash@5.3.9-r1 (GPL-3.0-or-later), readline@8.3.3-r1 (GPL-3.0-or-later), libncursesw/ncurses-terminfo-base (X11)) plus npm BlueOak-1.0.0 packages (minipass*, glob, lru-cache, chownr, tar, path-scurry, yallist, isexe, minimatch, common-ancestor-path). One package reports no licenses found: node@22.23.1, awf-cli-proxy@1.0.0 (local application package). curl/libcurl under curl license, qrcode-terminal (Apache 2.0), npm (Artistic-2.0), ca-certificates/ca-certificates-bundle (MPL-2.0), zlib (Zlib).
Remediation
- Upgrade
ip-address npm dependency to ≥10.3.1 and brace-expansion to fixed versions.
- Bump
node past 22.23.1 and undici/tar to fixed versions.
- Rebuild against a newer Alpine base for
busybox/nghttp2-libs fixes.
- Add license metadata/allowlist for the local
awf-cli-proxy@1.0.0 package and confirm node@22.23.1 license.
- Review Grant policy allowlist for standard Alpine GPL/LGPL/X11 base packages (bash, readline, ncurses are GPL/X11 by design).
Generated by 🛡️ Daily Container Image Security Scan · auto · 229 AIC · ⌖ 2.79 AIC · ⊞ 6.4K · ◷
Summary
Image:
ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.44Vulnerabilities
High
GHSA-rgw5-rvv9-x895:brace-expansion@5.0.7(fix: 5.0.9)GHSA-mh99-v99m-4gvg:brace-expansion@5.0.7(fix: 5.0.8)GHSA-mwp4-54f8-5fhr:ip-address@10.2.0(fix: 10.3.1)CVE-2026-58043:node@22.23.1(no fix version listed by Grype yet)Medium (12) and Low (2)
GHSA-4xrf-jv44-h6hh:ip-address@10.2.0(fix: 10.2.2)GHSA-22jq-vg5j-6vgg:ip-address@10.2.0(fix: 10.2.1)CVE-2025-60876:busybox@1.37.0-r31,busybox-binsh@1.37.0-r31,ssl_client@1.37.0-r31(no fix listed)CVE-2026-58040:node@22.23.1(fix: 22.23.2, 24.18.1, 26.5.1)CVE-2026-58055:nghttp2-libs@1.69.0-r0(no fix listed)GHSA-v3r7-h72x-cjcm,GHSA-8xcm-r25x-g524,GHSA-m8rv-5g2x-5cg5:undici@6.27.0(fix: 6.28.0)CVE-2026-56850:node@22.23.1(no fix listed)GHSA-r292-9mhp-454m:tar@7.5.19(fix: 7.5.21)CVE-2026-58039:node@22.23.1(fix: 22.23.2);CVE-2026-56847:node@22.23.1(no fix listed)License Policy Violations
40 violations. Alpine base-layer GPL-2.0/LGPL/GPL-3.0 packages (
busybox,apk-tools,alpine-baselayout,musl-utils,libgcc,libstdc++,libidn2,libunistring,zstd-libs,bash@5.3.9-r1(GPL-3.0-or-later),readline@8.3.3-r1(GPL-3.0-or-later),libncursesw/ncurses-terminfo-base(X11)) plus npmBlueOak-1.0.0packages (minipass*,glob,lru-cache,chownr,tar,path-scurry,yallist,isexe,minimatch,common-ancestor-path). One package reports no licenses found:node@22.23.1,awf-cli-proxy@1.0.0(local application package).curl/libcurlundercurllicense,qrcode-terminal(Apache 2.0),npm(Artistic-2.0),ca-certificates/ca-certificates-bundle(MPL-2.0),zlib(Zlib).Remediation
ip-addressnpm dependency to ≥10.3.1 andbrace-expansionto fixed versions.nodepast 22.23.1 andundici/tarto fixed versions.busybox/nghttp2-libsfixes.awf-cli-proxy@1.0.0package and confirmnode@22.23.1license.