Skip to content

[AW Top 10] 05 Consolidate container image scan CVE findings #65655

Description

@github-actions

Priority 5/10 | 16 source issues | Impact 3/5 | Confidence 3/5 | Effort 2/5

One assignment, one coherent fix

Sixteen container-image-scan issues report overlapping CVE findings for firewall, MCP gateway, GitHub MCP server, Serena and node images across several versions.

Implementation scope

Make the container image scan workflow update a single burn-down issue per image family, close findings for superseded image tags, and map remaining CVEs to an image bump or documented exception.

Done when

  • The scan updates one tracking issue per image instead of opening a new issue per tag.
  • Findings for image versions no longer referenced by the compiler are closed automatically.
  • Remaining CVEs are listed with a fix version or a recorded exception.

Why now

These issues are stale duplicates that add noise to the backlog and hide real image upgrades, and the fix is a local change to the scan workflow. Evidence is indirect because findings were not re-scanned during this pass.

AW source issues and corroborating reports

#51020 #51021 #51022 #51328 #51329 #51707 #51710 #52455 #52456 #52652 #52657 #52858 #53071 #53072 #53073 #53075

No corroborating AW discussion; evidence comes from the source issues.

Unchanged AW sources close only after this summary is completed. Newer source activity and not-planned retirement do not trigger source closure. Assigned summaries are frozen; unassign to allow reclustering.

Generated by AW Essential Issue Clustering · copilot · auto · 40.1 AIC · ⌖ 7.01 AIC · ⊞ 8.6K · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

agentic-workflowsautomationaw-essentialEssential AW-generated issue clusters: assign one to resolve related findingscookieIssue Monster Loves Cookies!

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions