Skip to content

fix(security): remove vulnerable gh-aw-firewall 0.27.42 container pins (agent, api-proxy, squid) - #49766

Merged
pelikhan merged 2 commits into
mainfrom
copilot/container-image-scan-remediation
Aug 2, 2026
Merged

fix(security): remove vulnerable gh-aw-firewall 0.27.42 container pins (agent, api-proxy, squid)#49766
pelikhan merged 2 commits into
mainfrom
copilot/container-image-scan-remediation

Conversation

Copilot AI commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

ghcr.io/github/gh-aw-firewall/agent:0.27.42 contains three High-severity CVEs (grpc GHSA-hrxh-6v49-42gf, brace-expansion GHSA-mh99-v99m-4gvg, golang.org/x/text GO-2026-5970). The default firewall version is already v0.27.43 with all workflow lock files updated; this removes the vulnerable 0.27.42 digests from shared pin metadata so they can no longer be resolved.

Changes

  • Lock source — removed agent:0.27.42, api-proxy:0.27.42, and squid:0.27.42 from .github/aw/actions-lock.json
  • Mirror sync — propagated same removals to pkg/actionpins/data/action_pins.json and pkg/workflow/data/action_pins.json
  • Changeset — documents the CVEs addressed

Follows the same pattern as the cli-proxy:0.27.42 removal (merged separately).

…s (agent, api-proxy, squid)

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Update container image and dependencies for ghcr.io/github/gh-aw-firewall/agent fix(security): remove vulnerable gh-aw-firewall 0.27.42 container pins (agent, api-proxy, squid) Aug 2, 2026
Copilot AI requested a review from pelikhan August 2, 2026 11:57
@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

PR Triage

  • Category:
  • Risk:
  • Priority: (score: 77/100)
    • Impact: 42/50, Urgency: 26/30, Quality: 9/20
  • Recommended action:
  • Batch:

Automated triage — see full report issue for details.

Structured data:

{
  "action": "fast_track",
  "category": "bug",
  "pr_number": 49766,
  "risk": "low"
}

Generated by 🔧 PR Triage Agent · auto · 73.4 AIC · ⌖ 3.47 AIC · ⊞ 8K ·

@pelikhan
pelikhan marked this pull request as ready for review August 2, 2026 12:50
Copilot AI review requested due to automatic review settings August 2, 2026 12:50
@pelikhan
pelikhan merged commit 02e2dde into main Aug 2, 2026
@pelikhan
pelikhan deleted the copilot/container-image-scan-remediation branch August 2, 2026 12:51

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Removes vulnerable gh-aw-firewall 0.27.42 container pins from shared metadata while retaining patched 0.27.43 pins.

Changes:

  • Removes agent, API proxy, and Squid 0.27.42 digests.
  • Synchronizes embedded pin mirrors.
  • Adds a patch changeset documenting the security fix.
Show a summary per file
File Description
.github/aw/actions-lock.json Removes vulnerable source pins.
pkg/actionpins/data/action_pins.json Updates action-pin embedded data.
pkg/workflow/data/action_pins.json Updates workflow embedded data.
.changeset/patch-remove-vulnerable-awf-0-27-42-pins.md Documents the security patch.

Review details

Tip

Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

  • Files reviewed: 4/4 changed files
  • Comments generated: 0
  • Review effort level: Balanced

@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.84.3

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/agent:0.27.42

3 participants