Skip to content

[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.44 #51021

Description

@github-actions

Summary

Image: ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.44

  • Vulnerabilities: 0 Critical / 4 High / 12 Medium / 2 Low / 0 Negligible
  • License policy violations: 40

Vulnerabilities

High

  • GHSA-rgw5-rvv9-x895: brace-expansion@5.0.7 (fix: 5.0.9)
  • GHSA-mh99-v99m-4gvg: brace-expansion@5.0.7 (fix: 5.0.8)
  • GHSA-mwp4-54f8-5fhr: ip-address@10.2.0 (fix: 10.3.1)
  • CVE-2026-58043: node@22.23.1 (no fix version listed by Grype yet)
Medium (12) and Low (2)
  • GHSA-4xrf-jv44-h6hh: ip-address@10.2.0 (fix: 10.2.2)
  • GHSA-22jq-vg5j-6vgg: ip-address@10.2.0 (fix: 10.2.1)
  • CVE-2025-60876: busybox@1.37.0-r31, busybox-binsh@1.37.0-r31, ssl_client@1.37.0-r31 (no fix listed)
  • CVE-2026-58040: node@22.23.1 (fix: 22.23.2, 24.18.1, 26.5.1)
  • CVE-2026-58055: nghttp2-libs@1.69.0-r0 (no fix listed)
  • GHSA-v3r7-h72x-cjcm, GHSA-8xcm-r25x-g524, GHSA-m8rv-5g2x-5cg5: undici@6.27.0 (fix: 6.28.0)
  • CVE-2026-56850: node@22.23.1 (no fix listed)
  • GHSA-r292-9mhp-454m: tar@7.5.19 (fix: 7.5.21)
  • Low: CVE-2026-58039: node@22.23.1 (fix: 22.23.2); CVE-2026-56847: node@22.23.1 (no fix listed)

License Policy Violations

40 violations. Alpine base-layer GPL-2.0/LGPL/GPL-3.0 packages (busybox, apk-tools, alpine-baselayout, musl-utils, libgcc, libstdc++, libidn2, libunistring, zstd-libs, bash@5.3.9-r1 (GPL-3.0-or-later), readline@8.3.3-r1 (GPL-3.0-or-later), libncursesw/ncurses-terminfo-base (X11)) plus npm BlueOak-1.0.0 packages (minipass*, glob, lru-cache, chownr, tar, path-scurry, yallist, isexe, minimatch, common-ancestor-path). One package reports no licenses found: node@22.23.1, awf-cli-proxy@1.0.0 (local application package). curl/libcurl under curl license, qrcode-terminal (Apache 2.0), npm (Artistic-2.0), ca-certificates/ca-certificates-bundle (MPL-2.0), zlib (Zlib).

Remediation

  1. Upgrade ip-address npm dependency to ≥10.3.1 and brace-expansion to fixed versions.
  2. Bump node past 22.23.1 and undici/tar to fixed versions.
  3. Rebuild against a newer Alpine base for busybox/nghttp2-libs fixes.
  4. Add license metadata/allowlist for the local awf-cli-proxy@1.0.0 package and confirm node@22.23.1 license.
  5. Review Grant policy allowlist for standard Alpine GPL/LGPL/X11 base packages (bash, readline, ncurses are GPL/X11 by design).

Generated by 🛡️ Daily Container Image Security Scan · auto · 229 AIC · ⌖ 2.79 AIC · ⊞ 6.4K · ◷

Activity

  1. github-actions commented on Aug 7, 2026

    @github-actions
    ContributorAuthor

    🍪 Issue Monster selected this for Copilot

    I've identified this issue as a good candidate for automated resolution and requested assignment to the Copilot coding agent.

    If assignment succeeds, the Copilot coding agent will analyze the issue and create a pull request with the fix.

    Om nom nom! 🍪

    🍪 Om nom nom by Issue Monster · gpt54 · 2.67 AIC · ⊞ 10.2K · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions