Skip to content

[uk-ai-resilience] [risk-review] Tier C: gh-aw-firewall & MCP-gateway container images have unpatched CVEs — apply tracked version bump #51825

Description

@github-actions

Tier & Risk Scoring

Tier: C — Restricted Pending Review

Dimension Rating
Exposure amplification Medium (images sit in the egress-control/tool-call execution path for all agentic workflows)
Patchability High (sibling MCP container images were already replaced/patched this week, proving the remediation pattern)
Detectability High (automated container-image-scan already flagging these)
Operational fragility Medium (the firewall stack is itself a security control — vulnerable firewall images undermine egress protections repo-wide)
Ownership confidence High (active remediation cadence observed for related images this week)

Affected Open Findings

Remediation Action

Apply the already-tracked version bump (#41554, target v0.27.11 for firewall components) and update gh-aw-mcpg and github-mcp-server pinned image tags to their latest patched releases. Re-run container-image-scan to confirm closure.

SLA Urgency: Critical (firewall/gateway images) / High (MCP server images) — this stack is a security control itself, so unpatched CVEs here have amplified downstream impact across every agentic workflow run.

Reference

Full analysis: see the UK AI Open Code Risk & Resilience Governance discussion report published this run ("UK AI Open Code Risk & Resilience Governance — Weekly Review (2026-08-10)").

Filed automatically by the UK AI Open Code Risk & Resilience Governance workflow, recent-changes lookback (7 days).

Generated by UK AI Operational Resilience · auto · 57.4 AIC · ⌖ 2.52 AIC · ⊞ 8.7K ·

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions