Overview
Image: ghcr.io/github/gh-aw-firewall/squid:0.27.44 — pinned reference:
ghcr.io/github/gh-aw-firewall/squid:0.27.44@sha256:83e48bbe12c634be8c228a576832fe45f66c529ac3659db92bddbcf2eeb6d627
Grype found: 14 High, 8 Medium (0 Critical/Low) across 63 packages. Grant found 37 license policy violations.
Key metrics
| Severity |
Count |
| Critical |
0 |
| High |
14 |
| Medium |
8 |
High severity vulnerabilities
14 High findings — all bind-libs/bind-tools@9.20.24-r0
Medium vulnerabilities
8 Medium findings
Additional lower-severity advisories in the Alpine base package set (squid/bind dependency chain). See raw scan log at /tmp/gh-aw/agent/image-scan/compile-output.txt (grep gh-aw-firewall/squid:0.27.44) for full detail.
License policy violations
37 rejected/unknown licenses
Alpine base-package GPL-2.0-only/MPL-2.0 family licenses (squid, bind, and Alpine baselayout dependencies).
Remediation
- Upgrade
bind-libs/bind-tools to >=9.20.26-r0 to resolve all 14 High CVEs in one step.
- Review Grant license policy allow-list for Alpine GPL/MPL packages if intentionally accepted.
- Daily
--force-refresh-container-pins run is the default remediation path once the fixed Alpine package set is published.
Generated by 🛡️ Daily Container Image Security Scan · auto · 295.8 AIC · ⌖ 10.1 AIC · ⊞ 6.9K · ◷
Overview
Image:
ghcr.io/github/gh-aw-firewall/squid:0.27.44— pinned reference:ghcr.io/github/gh-aw-firewall/squid:0.27.44@sha256:83e48bbe12c634be8c228a576832fe45f66c529ac3659db92bddbcf2eeb6d627Grype found: 14 High, 8 Medium (0 Critical/Low) across 63 packages. Grant found 37 license policy violations.
Key metrics
High severity vulnerabilities
14 High findings — all bind-libs/bind-tools@9.20.24-r0
Medium vulnerabilities
8 Medium findings
Additional lower-severity advisories in the Alpine base package set (squid/bind dependency chain). See raw scan log at
/tmp/gh-aw/agent/image-scan/compile-output.txt(grepgh-aw-firewall/squid:0.27.44) for full detail.License policy violations
37 rejected/unknown licenses
Alpine base-package
GPL-2.0-only/MPL-2.0family licenses (squid, bind, and Alpine baselayout dependencies).Remediation
bind-libs/bind-toolsto >=9.20.26-r0 to resolve all 14 High CVEs in one step.--force-refresh-container-pinsrun is the default remediation path once the fixed Alpine package set is published.