Skip to content

[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.43 #49506

Description

@github-actions

Summary

Image: ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.43
Pinned reference: ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.43@sha256:65c45ea2967984d0024f3df61bc71335658a77ede96c8d9665da7a5f33a795ab

  • Vulnerabilities: 9 total — Critical: 0, High: 3, Medium: 6, Low: 0, Negligible: 0, Unknown: 0
  • License policy violations: 40

Remediation

  • Rebuild/update the image to pull in patched packages for the vulnerabilities listed below (fixed versions shown where available).
  • Review the licenses listed below against policy; consider replacing, removing, or granting an exception for flagged packages.
  • Re-run the scan after remediation to confirm the findings are resolved.

Critical & High severity vulnerabilities

[High] GHSA-hrxh-6v49-42gf: google.golang.org/grpc@v1.81.1 (fix: 1.82.1) (https://github.com/advisories/GHSA-hrxh-6v49-42gf)
[High] GHSA-mh99-v99m-4gvg: brace-expansion@5.0.7 (fix: 5.0.8) (https://github.com/advisories/GHSA-mh99-v99m-4gvg)
[High] GO-2026-5970: golang.org/x/text@v0.38.0 (fix: 0.39.0) (https://go.dev/issue/80142)
Medium / Low / Negligible / Unknown vulnerabilities (6 findings, 6 unique)
[Medium] CVE-2025-60876: busybox-binsh@1.37.0-r31 ((nvd.nist.gov/redacted)
[Medium] CVE-2025-60876: busybox@1.37.0-r31 ((nvd.nist.gov/redacted)
[Medium] CVE-2025-60876: ssl_client@1.37.0-r31 ((nvd.nist.gov/redacted)
[Medium] CVE-2026-58055: nghttp2-libs@1.69.0-r0 ((nvd.nist.gov/redacted)
[Medium] GHSA-r292-9mhp-454m: tar@7.5.19 (fix: 7.5.21) (https://github.com/advisories/GHSA-r292-9mhp-454m)
[Medium] GO-2026-5856: stdlib@go1.26.4 (fix: 1.25.12, 1.26.5, 1.27.0-rc.2) (https://go.dev/cl/775960)
License policy violations (40 findings, 40 unique)
alpine-baselayout-data@3.7.2-r1 (GPL-2.0-only)
alpine-baselayout@3.7.2-r1 (GPL-2.0-only)
apk-tools@3.0.6-r0 (GPL-2.0-only)
awf-cli-proxy@1.0.0 (no licenses found)
bash@5.3.9-r1 (GPL-3.0-or-later)
busybox-binsh@1.37.0-r31 (GPL-2.0-only)
busybox@1.37.0-r31 (GPL-2.0-only)
ca-certificates-bundle@20260611-r0 (MPL-2.0)
ca-certificates@20260611-r0 (MPL-2.0)
chownr@3.0.0 (BlueOak-1.0.0)
common-ancestor-path@2.0.0 (BlueOak-1.0.0)
curl@8.21.0-r0 (curl)
glob@13.0.6 (BlueOak-1.0.0)
isexe@4.0.0 (BlueOak-1.0.0)
libapk@3.0.6-r0 (GPL-2.0-only)
libcurl@8.21.0-r0 (curl)
libgcc@15.2.0-r5 (GPL-2.0-or-later, LGPL-2.1-or-later)
libidn2@2.3.8-r0 (GPL-2.0-or-later, LGPL-3.0-or-later)
libncursesw@6.6_p20260516-r0 (X11)
libstdc++`@15`.2.0-r5 (GPL-2.0-or-later, LGPL-2.1-or-later)
libunistring@1.4.2-r0 (GPL-2.0-or-later, LGPL-3.0-or-later)
lru-cache@11.5.1 (BlueOak-1.0.0)
minimatch@10.2.5 (BlueOak-1.0.0)
minipass-flush@1.0.6 (BlueOak-1.0.0)
minipass@7.1.3 (BlueOak-1.0.0)
musl-utils@1.2.6-r2 (GPL-2.0-or-later)
ncurses-terminfo-base@6.6_p20260516-r0 (X11)
node@22.23.1 (no licenses found)
npm@11.18.0 (Artistic-2.0)
path-scurry@2.0.2 (BlueOak-1.0.0)
qrcode-terminal@0.12.0 (Apache 2.0)
readline@8.3.3-r1 (GPL-3.0-or-later)
scanelf@1.3.9-r1 (GPL-2.0-only)
spdx-exceptions@2.5.0 (CC-BY-3.0)
spdx-license-ids@3.0.23 (CC0-1.0)
ssl_client@1.37.0-r31 (GPL-2.0-only)
tar@7.5.19 (BlueOak-1.0.0)
yallist@5.0.0 (BlueOak-1.0.0)
zlib@1.3.2-r0 (Zlib)
zstd-libs@1.5.7-r2 (GPL-2.0-or-later)

Generated by 🛡️ Daily Container Image Security Scan · auto · 285.1 AIC · ⌖ 8.51 AIC · ⊞ 6.3K ·

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions