Skip to content

[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/api-proxy:0.27.42 #49085

Description

@github-actions

Summary

Image: ghcr.io/github/gh-aw-firewall/api-proxy:0.27.42

Severity Count
Critical 0
High 1
Medium 6
Low 0
Negligible 0
License violations 35

Remediation guidance

  • Rebuild from the latest gh-aw-firewall api-proxy base image to pick up upstream OS/library security patches.
  • Upgrade any bundled application dependencies to the fixed versions listed below.
  • Review GPL/LGPL/MPL-licensed OS packages against the repository license policy; typically acceptable but should be explicitly allow-listed.

Vulnerabilities

Click to expand 0C/1H/6M/0L/0N findings
error: [High] GHSA-mh99-v99m-4gvg: brace-expansion@5.0.7 (fix: 5.0.8)
warning: [Medium] CVE-2025-60876: busybox-binsh@1.37.0-r31
warning: [Medium] CVE-2025-60876: busybox@1.37.0-r31
warning: [Medium] CVE-2025-60876: ssl_client@1.37.0-r31
warning: [Medium] CVE-2026-58055: nghttp2-libs@1.69.0-r0
warning: [Medium] GHSA-8988-4f7v-96qf: `@opentelemetry/core`@1.30.1 (fix: 2.8.0)
warning: [Medium] GHSA-r292-9mhp-454m: tar@7.5.19 (fix: 7.5.21)

License violations

Click to expand 35 license findings
alpine-baselayout-data@3.7.2-r1 (GPL-2.0-only)
alpine-baselayout@3.7.2-r1 (GPL-2.0-only)
apk-tools@3.0.6-r0 (GPL-2.0-only)
awf-api-proxy@1.0.0 (no licenses found)
busybox-binsh@1.37.0-r31 (GPL-2.0-only)
busybox@1.37.0-r31 (GPL-2.0-only)
ca-certificates-bundle@20260611-r0 (MPL-2.0)
chownr@3.0.0 (BlueOak-1.0.0)
common-ancestor-path@2.0.0 (BlueOak-1.0.0)
curl@8.21.0-r0 (curl)
glob@13.0.6 (BlueOak-1.0.0)
isexe@4.0.0 (BlueOak-1.0.0)
libapk@3.0.6-r0 (GPL-2.0-only)
libcurl@8.21.0-r0 (curl)
libgcc@15.2.0-r5 (GPL-2.0-or-later, LGPL-2.1-or-later)
libidn2@2.3.8-r0 (GPL-2.0-or-later, LGPL-3.0-or-later)
libstdc++`@15`.2.0-r5 (GPL-2.0-or-later, LGPL-2.1-or-later)
libunistring@1.4.2-r0 (GPL-2.0-or-later, LGPL-3.0-or-later)
lru-cache@11.5.1 (BlueOak-1.0.0)
minimatch@10.2.5 (BlueOak-1.0.0)
minipass-flush@1.0.6 (BlueOak-1.0.0)
minipass@7.1.3 (BlueOak-1.0.0)
musl-utils@1.2.6-r2 (GPL-2.0-or-later)
node@22.23.1 (no licenses found)
npm@11.18.0 (Artistic-2.0)
path-scurry@2.0.2 (BlueOak-1.0.0)
qrcode-terminal@0.12.0 (Apache 2.0)
scanelf@1.3.9-r1 (GPL-2.0-only)
spdx-exceptions@2.5.0 (CC-BY-3.0)
spdx-license-ids@3.0.23 (CC0-1.0)
ssl_client@1.37.0-r31 (GPL-2.0-only)
tar@7.5.19 (BlueOak-1.0.0)
yallist@5.0.0 (BlueOak-1.0.0)
zlib@1.3.2-r0 (Zlib)
zstd-libs@1.5.7-r2 (GPL-2.0-or-later)

Generated by 🛡️ Daily Container Image Security Scan · auto · 389.1 AIC · ⌖ 11.3 AIC · ⊞ 6.3K · ◷

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions