Skip to content

[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.44 #51021

Description

@github-actions

Summary

Image: ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.44

  • Vulnerabilities: 0 Critical / 4 High / 12 Medium / 2 Low / 0 Negligible
  • License policy violations: 40

Vulnerabilities

High

  • GHSA-rgw5-rvv9-x895: brace-expansion@5.0.7 (fix: 5.0.9)
  • GHSA-mh99-v99m-4gvg: brace-expansion@5.0.7 (fix: 5.0.8)
  • GHSA-mwp4-54f8-5fhr: ip-address@10.2.0 (fix: 10.3.1)
  • CVE-2026-58043: node@22.23.1 (no fix version listed by Grype yet)
Medium (12) and Low (2)
  • GHSA-4xrf-jv44-h6hh: ip-address@10.2.0 (fix: 10.2.2)
  • GHSA-22jq-vg5j-6vgg: ip-address@10.2.0 (fix: 10.2.1)
  • CVE-2025-60876: busybox@1.37.0-r31, busybox-binsh@1.37.0-r31, ssl_client@1.37.0-r31 (no fix listed)
  • CVE-2026-58040: node@22.23.1 (fix: 22.23.2, 24.18.1, 26.5.1)
  • CVE-2026-58055: nghttp2-libs@1.69.0-r0 (no fix listed)
  • GHSA-v3r7-h72x-cjcm, GHSA-8xcm-r25x-g524, GHSA-m8rv-5g2x-5cg5: undici@6.27.0 (fix: 6.28.0)
  • CVE-2026-56850: node@22.23.1 (no fix listed)
  • GHSA-r292-9mhp-454m: tar@7.5.19 (fix: 7.5.21)
  • Low: CVE-2026-58039: node@22.23.1 (fix: 22.23.2); CVE-2026-56847: node@22.23.1 (no fix listed)

License Policy Violations

40 violations. Alpine base-layer GPL-2.0/LGPL/GPL-3.0 packages (busybox, apk-tools, alpine-baselayout, musl-utils, libgcc, libstdc++, libidn2, libunistring, zstd-libs, bash@5.3.9-r1 (GPL-3.0-or-later), readline@8.3.3-r1 (GPL-3.0-or-later), libncursesw/ncurses-terminfo-base (X11)) plus npm BlueOak-1.0.0 packages (minipass*, glob, lru-cache, chownr, tar, path-scurry, yallist, isexe, minimatch, common-ancestor-path). One package reports no licenses found: node@22.23.1, awf-cli-proxy@1.0.0 (local application package). curl/libcurl under curl license, qrcode-terminal (Apache 2.0), npm (Artistic-2.0), ca-certificates/ca-certificates-bundle (MPL-2.0), zlib (Zlib).

Remediation

  1. Upgrade ip-address npm dependency to ≥10.3.1 and brace-expansion to fixed versions.
  2. Bump node past 22.23.1 and undici/tar to fixed versions.
  3. Rebuild against a newer Alpine base for busybox/nghttp2-libs fixes.
  4. Add license metadata/allowlist for the local awf-cli-proxy@1.0.0 package and confirm node@22.23.1 license.
  5. Review Grant policy allowlist for standard Alpine GPL/LGPL/X11 base packages (bash, readline, ncurses are GPL/X11 by design).

Generated by 🛡️ Daily Container Image Security Scan · auto · 229 AIC · ⌖ 2.79 AIC · ⊞ 6.4K ·

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions