Skip to content

[container-image-scan] Correction needed: accidental placeholder update to #52657 #62888

Description

@github-actions

Operational note: #52657 needs manual correction this cycle

While preparing this run's update to the Container CVE burn-down tracker (#52657), an accidental placeholder update_issue call (body: test, operation: prepend) was submitted before the real scan summary could be sent. This workflow's update_issue safe-output is limited to 1 call per run, so that placeholder call consumed the quota and the correct summary below could not be applied to #52657 in this run.

Action needed: A maintainer (or the next scheduled run) should:

  1. Remove the stray prepended test text from the top of [container-image-scan] Container CVE burn-down #52657's body.
  2. Replace/prepend [container-image-scan] Container CVE burn-down #52657's body with the correct scan summary reproduced in full below.

Correct scan summary for #52657 (workflow run 35822817812)

Overview

Consolidated Critical/High CVE and license burn-down tracker for the daily container image security scan. Per-image detail issues are not created; all findings are tracked here.

Scan run

Compiled with gh aw compile --force-refresh-container-pins. Workflow run: 35822817812.

Summary table (ordered Critical → High → Medium → Low → Unknown/Negligible)

Image Pinned ref Class Critical High Medium Low Unknown Negligible License violations
ghcr.io/oraios/serena 1.7.0@sha256:6c9459e... Upstream (oraios/serena, 3rd-party) 12 227 raw / 98 unique 188 37 36 719 0
ghcr.io/xberg-io/xberg latest@sha256:1d9e51a... Upstream (xberg-io, kreuzberg MCP, 3rd-party) 18 90 raw / 39 unique 69 12 1 112 47
ghcr.io/github/gh-aw-mcpg v0.4.25@sha256:9be0a86... Upstream (github/gh-aw-mcpg) 4 55 raw / 50 unique 21 7 7 0 0
grafana/mcp-grafana 1.1.0-alpine@sha256:e0eb29c... Upstream (Grafana Labs, 3rd-party) 4 21 raw / 19 unique 3 3 0 0 0
node (base for gh-aw-node) lts-alpine@sha256:ebfe2f9... Upstream (Docker Official node) 0 5 8 0 0 0 0
ghcr.io/github/github-mcp-server v1.12.2@sha256:508a085... Upstream (github/github-mcp-server, 3rd-party build) 1 4 10 1 0 8 0
ghcr.io/github/gh-aw-firewall/api-proxy 0.28.23@sha256:c15c3d1... Upstream (github/gh-aw-firewall) 0 5 9 0 0 0 1
ghcr.io/github/gh-aw-firewall/cli-proxy 0.28.23@sha256:9e31a6e... Upstream (github/gh-aw-firewall) 0 5 9 0 0 0 1
ghcr.io/github/gh-aw-firewall/agent 0.28.23@sha256:2c78aab... Upstream (github/gh-aw-firewall) 0 4 313 47 0 19 32
ghcr.io/github/gh-aw-firewall/squid 0.28.23@sha256:02ffc56... Upstream (github/gh-aw-firewall) 0 1 4 0 0 0 11
ghcr.io/github/gh-aw-node sha256:11c2c54... (base: node:lts-alpine, refreshed this run) Vendored (built from /actions/setup/js/Dockerfile.safe-outputs-mcp in this repo) 0 1 4 0 0 0 0

Totals: 39 Critical, 445 raw High findings (≈257 unique advisories) across 11 scanned images. License policy violations: 92, across 5 images (all upstream, no vendored-code fix possible here).

Per-image detail

ghcr.io/oraios/serena — Upstream — 12 Critical, 98 unique High

Classification: Upstream — tracked only. Image is owned/built by oraios/serena (third party, Debian trixie base). No code-level fix can land in github/gh-aw.

Critical (12 rows, 4 unique advisories):

  • CVE-2026-19931 — curl/libcurl3t64-gnutls/libcurl4t64 @8.14.1-2+deb13u4 (no fix yet)
  • CVE-2026-18924 — curl/libcurl3t64-gnutls/libcurl4t64 @8.14.1-2+deb13u4 (no fix yet)
  • CVE-2026-63073 — libssl3t64/openssl/openssl-provider-legacy @3.5.6-1deb13u2 (fix: 3.5.7-1deb13u2)
  • CVE-2026-75803 — libssl3t64/openssl/openssl-provider-legacy @3.5.6-1deb13u2 (fix: 3.5.7-1deb13u2)

High (98 unique advisory IDs, selected highlights — full list omitted for compactness):

Remediation: Upstream — tracked only. Awaiting oraios/serena to rebuild 1.7.0/latest on a refreshed Debian trixie + Node.js + Python base and bump bundled npm/pip deps. Daily pin-refresh workflow will pick up a new digest automatically once published. No advisory/issue link found yet in the oraios/serena upstream tracker for these specific CVEs.

ghcr.io/xberg-io/xberg — Upstream — 18 Critical, 39 unique High, 47 license violations

Classification: Upstream — tracked only. Image is owned by xberg-io (third-party kreuzberg MCP image, referenced from .github/workflows/shared/mcp/kreuzberg.md). No code-level fix can land in github/gh-aw.

Critical (18 rows, 8 unique advisories) — all Debian trixie packages, no fix yet unless noted:

High (39 unique advisories, highlights):

License violations (47): copyleft/weak-copyleft (GPL/LGPL/MPL family) and permissive-with-notice licenses on Debian system packages bundled in the image (libglib2.0-0t64, libssl3t64, fontconfig, libpango*, libnghttp3-9, libpsl5t64, tini, login.defs, libaom3, libx265-215, libldap2, and others) — none introduced by this repo.

Remediation: Upstream — tracked only. Requires xberg-io/xberg to rebuild on a refreshed Debian trixie base with bumped curl, libxml2, tesseract-ocr, util-linux, and libexpat1 packages. Daily pin-refresh picks up a new digest automatically once published; no advisory/issue link found yet in the upstream xberg-io tracker.

ghcr.io/github/gh-aw-mcpg — Upstream — 4 Critical, 50 unique High

Classification: Upstream — tracked only (owned by github/gh-aw-mcpg).

Critical (4 rows, 2 unique advisories):

High (50 unique advisories, highlights):

  • Go stdlib@go1.26.3/go1.26.4 (fix: 1.25.11–1.25.13, 1.26.4–1.26.6, 1.27.0-rc.2/3): GO-2026-5026, GO-2026-6089, GO-2026-6090, GO-2026-5972, GO-2026-5942, GO-2026-4970, GO-2026-5037
  • golang.org/x/text @v0.38.0 (fix: 0.39.0): GO-2026-5970
  • golang.org/x/crypto @v0.53.0 (fix: 0.56.0): GO-2026-6354, GO-2026-6355
  • google.golang.org/grpc @v1.81.1/v1.83.1 (fix: 1.82.1–1.83.2): GHSA-2v4p-qf9q-27wj, GHSA-hrxh-6v49-42gf, GHSA-vp52-pcj8-j9qc
  • github.com/sigstore/fulcio @v1.8.5 (fix: 1.8.6): GHSA-f5mr-q85p-6hh6
  • github.com/moby/go-archive @v0.2.0 (fix: 0.3.0): GHSA-hfg8-hc9c-6c3h
  • Alpine libcrypto3/libssl3 @3.5.7-r0 (fix: 3.5.8-r0): CVE-2026-18798, CVE-2026-63072, CVE-2026-63075, CVE-2026-63076, CVE-2026-14456, CVE-2026-14457, CVE-2026-54874
  • Alpine libblkid/libmount @2.42.1-r0 (fix: 2.42.3-r0/r1): CVE-2026-76642, CVE-2026-78408, CVE-2026-78409, CVE-2026-78410
  • Alpine pcre2 @10.47-r1 (no fix yet): CVE-2026-89157, CVE-2026-89161
  • docker-cli @29.5.3-r0 (no fix yet): CVE-2026-17106
  • zlib @1.3.2-r0 (no fix yet): CVE-2026-85091

Remediation: Upstream — tracked only. Requires github/gh-aw-mcpg to rebuild with a newer Go toolchain, bumped x/text/x/crypto/fulcio/grpc/moby/go-archive module versions, and an Alpine base bump. Daily pin-refresh in this repo picks up a new gh-aw-mcpg release once published.

grafana/mcp-grafana — Upstream — 4 Critical, 19 unique High

Classification: Upstream — tracked only (Grafana Labs, third party).

Critical (4 rows, 2 unique advisories):

High:

Remediation: Upstream — tracked only. Awaiting Grafana Labs to rebuild 1.1.0-alpine on a refreshed Alpine base and a newer grpc-go dependency. Daily pin-refresh picks this up automatically once published.

node:lts-alpine (base for gh-aw-node) — Upstream — 0 Critical, 5 High

Classification: Upstream — tracked only (Docker Official Images node; also the base layer for the vendored ghcr.io/github/gh-aw-node image).

Remediation: Upstream — tracked only. Node.js/Alpine packages are inherited from the node:lts-alpine Docker Official Image. The daily pin-refresh already bumps node:lts-alpine as new tags publish; no local code fix applies to this base layer. The prior Critical tar advisory (GHSA-23hp-3jrh-7fpw) is no longer present in this scan.

ghcr.io/github/github-mcp-server — Upstream — 1 Critical, 4 High

Classification: Upstream — tracked only (owned by github/github-mcp-server, third-party build, Debian-based).

Also 10 Medium, 1 Low, 8 Negligible (mostly libc6/libssl3 legacy CVEs with limited practical impact).

Remediation: Upstream — tracked only. Requires github/github-mcp-server to refresh its Debian base image. Daily pin-refresh picks up a new github-mcp-server release once published.

ghcr.io/github/gh-aw-firewall/api-proxy & cli-proxy — Upstream — 0 Critical, 5 High each

Classification: Upstream — tracked only (owned by github/gh-aw-firewall).

License violation (1 each): awf-api-proxy@1.0.0 / awf-cli-proxy@1.0.0 — no licenses found (internal package metadata, upstream-owned).

Remediation: Upstream — tracked only. Requires github/gh-aw-firewall to bump brace-expansion/tar/ip-address npm deps and refresh the Alpine base. Daily pin-refresh picks up new gh-aw-firewall releases automatically.

ghcr.io/github/gh-aw-firewall/agent — Upstream — 0 Critical, 4 High

Classification: Upstream — tracked only (owned by github/gh-aw-firewall).

Also carries 313 Medium and 47 Low findings (predominantly Ubuntu 22.04 bind9-libs, curl/libcurl4, perl family — not itemized here per compactness) plus 32 license policy violations (GPL/LGPL/MPL/HPND system packages such as libpango*, libavahi-*, libnss3, libcups2, fonts-liberation, and one "no licenses found" package fonts-liberation).

Remediation: Upstream — tracked only, same npm-dependency family as api-proxy/cli-proxy. License violations are Alpine/Ubuntu system-package licenses bundled transitively via the upstream image base — not introduced by this repo, and cannot be fixed here.

ghcr.io/github/gh-aw-firewall/squid — Upstream — 0 Critical, 1 High

Classification: Upstream — tracked only (owned by github/gh-aw-firewall).

  • CVE-2026-85091 — zlib @1.3.2-r0 (no fix yet)

License violations (11): xz-libs (0BSD/AND/GPL-2.0-or-later/LGPL-2.1-or-later/Public-Domain), acl-libs (LGPL-2.1-or-later/GPL-2.0-or-later), mii-tool (GPL-2.0-or-later), keyutils-libs (GPL-2.0-or-later/LGPL-2.0-or-later), bind-libs (MPL-2.0), squid (GPL-2.0-or-later), userspace-rcu (LGPL-2.1-or-later), libcom_err (GPL-2.0-or-later/LGPL-2.0-or-later), logrotate (GPL-2.0-or-later), bind-tools (MPL-2.0), libltdl (LGPL-2.0-or-later/GPL-2.0-or-later).

Remediation: Upstream — tracked only. Alpine base refresh needed for zlib. The license violations are Grant policy flags on copyleft/weak-copyleft licenses bundled transitively via Alpine packages inside the upstream squid image — not introduced by this repo, and expected/acceptable for these system packages unless gh-aw-firewall's Grant policy changes upstream.

ghcr.io/github/gh-aw-node — Vendored — 0 Critical, 1 High

Classification: Vendored. Built from /actions/setup/js/Dockerfile.safe-outputs-mcp in this repository (github/gh-aw), published by .github/workflows/publish-safe-outputs-node.yml. Base pinned to node:lts-alpine, refreshed this run to sha256:11c2c544876cdbaffefe0f7f1283b74838c209654b4934a78e23ed11f750490f.

  • [High] CVE-2026-85091 — zlib @1.3.2-r0 (no fix yet)
  • Also 4 Medium findings from the same base layer.

All findings are inherited from the node:lts-alpine base layer (Alpine zlib package), not from repo-specific Dockerfile content. Remediation here is limited to relying on the daily --force-refresh-container-pins Alpine base bump; no further vendored code change is actionable until Alpine ships a fixed zlib package.

Remediation SLA

  • Critical findings are remediated or explicitly risk-accepted within 7 days.
  • High findings are remediated within 30 days.
  • Every scanned image is rebuilt on a refreshed base image at least weekly — this workflow runs gh aw compile --force-refresh-container-pins daily, so a pin refresh PR is the default remediation step for base-image-sourced findings.
  • For findings on upstream images (all findings in this run except the one High/four Medium items on ghcr.io/github/gh-aw-node, which are also base-layer-inherited), no local code-fix PR is requested here — the daily pin-refresh already picks up upstream fixes automatically once released. These are labeled Upstream — tracked only above.

Next actions

  • ghcr.io/xberg-io/xberg (18 Critical, 39 unique High, 47 license violations) is a newly-scanned image this run and now the second-largest remediation burden after oraios/serena — both fully upstream/third-party.
  • oraios/serena (98 unique High CVEs, 12 Critical) remains the largest remediation burden — all upstream, awaiting a rebuilt oraios/serena release with refreshed curl/openssl/Node.js/Python.
  • ghcr.io/github/gh-aw-mcpg and grafana/mcp-grafana share the same Alpine openssl Critical (CVE-2026-63073, CVE-2026-75803) — a single Alpine security update resolves both once published.
  • gh-aw-firewall/agent, api-proxy, cli-proxy share the same brace-expansion/tar/ip-address npm advisories — a single upstream fix in github/gh-aw-firewall resolves all three.
  • License policy violations (92 total: 47 on xberg-io/xberg, 32 on gh-aw-firewall/agent, 11 on gh-aw-firewall/squid, 1 each on api-proxy/cli-proxy) are all upstream system-package licenses (GPL/LGPL/MPL/HPND) or "no licenses found" internal packages — not fixable from this repo; track only if the respective upstream Grant policy changes.
  • Track this issue until all per-image Critical/High counts reach zero or are explicitly risk-accepted.

Sorry for the noise — this issue documents an internal workflow mistake so the correct content isn't lost, and it can be closed once #52657 is manually corrected.

Generated by 🛡️ Daily Container Image Security Scan · copilot · auto · 380.3 AIC · ⌖ 8.1 AIC · ⊞ 7.7K · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions