Skip to content

[container-image-scan] test title #49503

Description

@github-actions

Summary

Image: ghcr.io/github/gh-aw-node
Pinned reference: ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748

  • Vulnerabilities: 6 total — Critical: 0, High: 1, Medium: 5, Low: 0, Negligible: 0, Unknown: 0
  • License policy violations: 35

Remediation

  • Rebuild/update the image to pull in patched packages for the vulnerabilities listed below (fixed versions shown where available).
  • Review the licenses listed below against policy; consider replacing, removing, or granting an exception for flagged packages.
  • Re-run the scan after remediation to confirm the findings are resolved.

Critical & High severity vulnerabilities

[High] GHSA-mh99-v99m-4gvg: brace-expansion@5.0.7 (fix: 5.0.8) (https://github.com/advisories/GHSA-mh99-v99m-4gvg)
Medium / Low / Negligible / Unknown vulnerabilities (5 findings, 5 unique)
[Medium] CVE-2025-60876: busybox-binsh@1.37.0-r31 ((nvd.nist.gov/redacted)
[Medium] CVE-2025-60876: busybox@1.37.0-r31 ((nvd.nist.gov/redacted)
[Medium] CVE-2025-60876: ssl_client@1.37.0-r31 ((nvd.nist.gov/redacted)
[Medium] CVE-2026-58055: nghttp2-libs@1.69.0-r0 ((nvd.nist.gov/redacted)
[Medium] GHSA-r292-9mhp-454m: tar@7.5.19 (fix: 7.5.21) (https://github.com/advisories/GHSA-r292-9mhp-454m)
License policy violations (35 findings, 35 unique)
alpine-baselayout-data@3.7.2-r1 (GPL-2.0-only)
alpine-baselayout@3.7.2-r1 (GPL-2.0-only)
apk-tools@3.0.6-r0 (GPL-2.0-only)
busybox-binsh@1.37.0-r31 (GPL-2.0-only)
busybox@1.37.0-r31 (GPL-2.0-only)
ca-certificates-bundle@20260611-r0 (MPL-2.0)
chownr@3.0.0 (BlueOak-1.0.0)
common-ancestor-path@2.0.0 (BlueOak-1.0.0)
git-init-template@2.54.0-r0 (GPL-2.0-only)
git@2.54.0-r0 (GPL-2.0-only)
glob@13.0.6 (BlueOak-1.0.0)
isexe@4.0.0 (BlueOak-1.0.0)
libapk@3.0.6-r0 (GPL-2.0-only)
libcurl@8.21.0-r0 (curl)
libgcc@15.2.0-r5 (GPL-2.0-or-later, LGPL-2.1-or-later)
libidn2@2.3.8-r0 (GPL-2.0-or-later, LGPL-3.0-or-later)
libstdc++`@15`.2.0-r5 (GPL-2.0-or-later, LGPL-2.1-or-later)
libunistring@1.4.2-r0 (GPL-2.0-or-later, LGPL-3.0-or-later)
lru-cache@11.5.1 (BlueOak-1.0.0)
minimatch@10.2.5 (BlueOak-1.0.0)
minipass-flush@1.0.6 (BlueOak-1.0.0)
minipass@7.1.3 (BlueOak-1.0.0)
musl-utils@1.2.6-r2 (GPL-2.0-or-later)
node@24.18.0 (no licenses found)
npm@11.18.0 (Artistic-2.0)
path-scurry@2.0.2 (BlueOak-1.0.0)
qrcode-terminal@0.12.0 (Apache 2.0)
scanelf@1.3.9-r1 (GPL-2.0-only)
spdx-exceptions@2.5.0 (CC-BY-3.0)
spdx-license-ids@3.0.23 (CC0-1.0)
ssl_client@1.37.0-r31 (GPL-2.0-only)
tar@7.5.19 (BlueOak-1.0.0)
yallist@5.0.0 (BlueOak-1.0.0)
zlib@1.3.2-r0 (Zlib)
zstd-libs@1.5.7-r2 (GPL-2.0-or-later)

Generated by 🛡️ Daily Container Image Security Scan · auto · 285.1 AIC · ⌖ 8.51 AIC · ⊞ 6.3K · ◷

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions