Node scan summary
Status: Upstream (Alpine-based gh-aw-node / node:lts-alpine; no Dockerfile in this repo). Unique finding rows: 0 Critical, 29 High, 40 Medium, 17 Low, 0 Unknown; 0 license violations.
| Image |
Status |
Crit |
High |
Med |
Low |
Unk |
License |
| gh-aw-node |
upstream |
0 |
12 |
15 |
8 |
0 |
0 |
| node:lts-alpine |
upstream |
0 |
17 |
25 |
9 |
0 |
0 |
Images
| Image |
Pinned reference |
Status |
| gh-aw-node |
ghcr.io/github/gh-aw-node@sha256:11c2c544876cdbaffefe0f7f1283b74838c209654b4934a78e23ed11f750490f |
upstream |
| node:lts-alpine |
node:lts-alpine@sha256:ebfe2f90462722a7a4de65e91990e97fe0d401c70e0e762c5b53302f905ec1c1 |
upstream |
Findings by severity
gh-aw-node
High
CVE-2026-103111: pcre2@10.48-r0 (fix: 10.49-r0)
CVE-2026-54873: libcrypto3@3.5.8-r0
CVE-2026-54873: libssl3@3.5.8-r0
CVE-2026-72897: libcrypto3@3.5.8-r0
CVE-2026-72897: libssl3@3.5.8-r0
CVE-2026-84782: libcrypto3@3.5.8-r0
CVE-2026-84782: libssl3@3.5.8-r0
CVE-2026-84784: libcrypto3@3.5.8-r0
CVE-2026-84784: libssl3@3.5.8-r0
CVE-2026-85091: zlib@1.3.2-r0 (fix: 1.3.2-r1)
CVE-2026-93990: libexpat@2.8.4-r0 (fix: 2.8.5-r0)
GHSA-ch52-4w7c-c8xp: http-cache-semantics@4.2.0
Medium
CVE-2025-60876: busybox-binsh@1.37.0-r31
CVE-2025-60876: busybox@1.37.0-r31
CVE-2025-60876: ssl_client@1.37.0-r31
CVE-2026-35189: libcrypto3@3.5.8-r0
CVE-2026-35189: libssl3@3.5.8-r0
CVE-2026-42772: libcrypto3@3.5.8-r0
CVE-2026-42772: libssl3@3.5.8-r0
CVE-2026-58055: nghttp2-libs@1.69.0-r0 (fix: 1.70.0-r0)
CVE-2026-75804: libcrypto3@3.5.8-r0
CVE-2026-75804: libssl3@3.5.8-r0
CVE-2026-75805: libcrypto3@3.5.8-r0
CVE-2026-75805: libssl3@3.5.8-r0
CVE-2026-75806: libcrypto3@3.5.8-r0
CVE-2026-75806: libssl3@3.5.8-r0
GHSA-rj75-hqrm-r3gf: postcss-selector-parser@7.1.4 (fix: 7.1.6)
Low
CVE-2026-35191: libcrypto3@3.5.8-r0
CVE-2026-35191: libssl3@3.5.8-r0
CVE-2026-54872: libcrypto3@3.5.8-r0
CVE-2026-54872: libssl3@3.5.8-r0
CVE-2026-54875: libcrypto3@3.5.8-r0
CVE-2026-54875: libssl3@3.5.8-r0
CVE-2026-77696: libcrypto3@3.5.8-r0
CVE-2026-77696: libssl3@3.5.8-r0
node-lts-alpine
High
CVE-2026-54873: libcrypto3@3.5.8-r0
CVE-2026-54873: libssl3@3.5.8-r0
CVE-2026-72897: libcrypto3@3.5.8-r0
CVE-2026-72897: libssl3@3.5.8-r0
CVE-2026-84782: libcrypto3@3.5.8-r0
CVE-2026-84782: libssl3@3.5.8-r0
CVE-2026-84784: libcrypto3@3.5.8-r0
CVE-2026-84784: libssl3@3.5.8-r0
CVE-2026-85091: zlib@1.3.2-r0 (fix: 1.3.2-r1)
GHSA-6j4f-fj2g-mc7p: brace-expansion@5.0.7 (fix: 5.0.10)
GHSA-ch52-4w7c-c8xp: http-cache-semantics@4.2.0
GHSA-mh99-v99m-4gvg: brace-expansion@5.0.7 (fix: 5.0.8)
GHSA-mwp4-54f8-5fhr: ip-address@10.2.0 (fix: 10.3.1)
GHSA-qhr7-859c-m2p7: brace-expansion@5.0.7 (fix: 5.0.11)
GHSA-r292-9mhp-454m: tar@7.5.19 (fix: 7.5.21)
GHSA-rfgv-xxqx-mfg5: undici@6.27.0 (fix: 6.28.1)
GHSA-rgw5-rvv9-x895: brace-expansion@5.0.7 (fix: 5.0.9)
Medium
CVE-2025-60876: busybox-binsh@1.37.0-r31
CVE-2025-60876: busybox@1.37.0-r31
CVE-2025-60876: ssl_client@1.37.0-r31
CVE-2026-35189: libcrypto3@3.5.8-r0
CVE-2026-35189: libssl3@3.5.8-r0
CVE-2026-42772: libcrypto3@3.5.8-r0
CVE-2026-42772: libssl3@3.5.8-r0
CVE-2026-75804: libcrypto3@3.5.8-r0
CVE-2026-75804: libssl3@3.5.8-r0
CVE-2026-75805: libcrypto3@3.5.8-r0
CVE-2026-75805: libssl3@3.5.8-r0
CVE-2026-75806: libcrypto3@3.5.8-r0
CVE-2026-75806: libssl3@3.5.8-r0
GHSA-22jq-vg5j-6vgg: ip-address@10.2.0 (fix: 10.2.1)
GHSA-2vr4-cq9g-pvrc: ip-address@10.2.0 (fix: 10.5.1)
GHSA-3wwx-pv8p-q78v: undici@6.27.0 (fix: 6.28.1)
GHSA-4xrf-jv44-h6hh: ip-address@10.2.0 (fix: 10.2.2)
GHSA-8xcm-r25x-g524: undici@6.27.0 (fix: 6.28.0)
GHSA-h3mg-xc3c-68pw: ip-address@10.2.0 (fix: 10.7.1)
GHSA-j6r3-76f7-8jcv: ip-address@10.2.0 (fix: 10.7.1)
GHSA-m8rv-5g2x-5cg5: undici@6.27.0 (fix: 6.28.0)
GHSA-q2hr-2g5m-vwhr: brace-expansion@5.0.7 (fix: 5.0.12)
GHSA-rj75-hqrm-r3gf: postcss-selector-parser@7.1.4 (fix: 7.1.6)
GHSA-rpw4-54j3-4h4q: ip-address@10.2.0 (fix: 10.5.1)
GHSA-v3r7-h72x-cjcm: undici@6.27.0 (fix: 6.28.0)
Low
CVE-2026-35191: libcrypto3@3.5.8-r0
CVE-2026-35191: libssl3@3.5.8-r0
CVE-2026-54872: libcrypto3@3.5.8-r0
CVE-2026-54872: libssl3@3.5.8-r0
CVE-2026-54875: libcrypto3@3.5.8-r0
CVE-2026-54875: libssl3@3.5.8-r0
CVE-2026-77696: libcrypto3@3.5.8-r0
CVE-2026-77696: libssl3@3.5.8-r0
GHSA-r53p-7pc4-xj5r: undici@6.27.0 (fix: 6.28.1)
Remediation and SLA
- SLA cadence: Critical findings are remediated or explicitly risk-accepted (by a maintainer) within 7 days; High within 30 days; every scanned image is rebuilt on a refreshed base image at least weekly. The daily scan runs
gh aw compile --force-refresh-container-pins, so a pin-refresh PR is the default remediation step.
- Status: Upstream — tracked only. These images are not built from a Dockerfile in
github/gh-aw; a code-level fix cannot land here. Do not request a local patch PR. The daily pin refresh picks up upstream fixes once released.
- Fixed versions: rows shown as
pkg@installed => fixed list the fixed package version reported by Grype. The image release/digest containing each fix has not been confirmed from this scan; rows with no fix listed have no fixed package version reported.
- Exceptions (not risk-accepted; pending maintainer approval): every finding above is awaiting a refreshed upstream image. Responsible project: the image's owning repository (see family summary). Next review: 2026-10-17 (weekly rebuild cadence).
- Findings are ordered by severity (Critical, High, Medium, Low, Unknown); rows are unique
ID pkg@version entries from the scan.
Generated by 🛡️ Daily Container Image Security Scan · copilot · auto · 190.8 AIC · ⌖ 0.9 AIC · ⊞ 8.5K · ◷
Node scan summary
Status: Upstream (Alpine-based
gh-aw-node/node:lts-alpine; no Dockerfile in this repo). Unique finding rows: 0 Critical, 29 High, 40 Medium, 17 Low, 0 Unknown; 0 license violations.Images
ghcr.io/github/gh-aw-node@sha256:11c2c544876cdbaffefe0f7f1283b74838c209654b4934a78e23ed11f750490fnode:lts-alpine@sha256:ebfe2f90462722a7a4de65e91990e97fe0d401c70e0e762c5b53302f905ec1c1Findings by severity
gh-aw-node
High
Medium
Low
node-lts-alpine
High
Medium
Low
Remediation and SLA
gh aw compile --force-refresh-container-pins, so a pin-refresh PR is the default remediation step.github/gh-aw; a code-level fix cannot land here. Do not request a local patch PR. The daily pin refresh picks up upstream fixes once released.pkg@installed => fixedlist the fixed package version reported by Grype. The image release/digest containing each fix has not been confirmed from this scan; rows with no fix listed have no fixed package version reported.ID pkg@versionentries from the scan.