Skip to content

[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/cli-proxy #52455

Description

@github-actions

Summary

Image: ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.44@sha256:9c1a2f77e0...

5 High, 14 Medium, 3 Low vulnerabilities (same Node.js runtime findings as api-proxy); 40 license policy violations.

Remediation

  • Update Node.js to >= 22.23.2 / 24.18.1 / 26.5.1 to resolve all node@22.23.1 CVEs.
  • Update brace-expansion to >= 5.0.9, ip-address to >= 10.3.1, undici to >= 6.28.0, tar to >= 7.5.21.
  • Update Alpine busybox/ssl_client/nghttp2-libs once patched packages are published (CVE-2025-60876, CVE-2026-58055).
  • License violations are largely standard Alpine base-layer GPL-2.0/LGPL/X11 packages and Node/npm bundled BlueOak-1.0.0 dependencies — treat as accepted policy exception for base-OS/npm-runtime packages. awf-cli-proxy@1.0.0 (no licenses found) is the first-party package and should have a license field added.

Vulnerabilities

22 vulnerabilities, primarily Node.js core and its bundled deps
Severity ID Package Installed Fixed
High CVE-2026-56846 node 22.23.1 22.23.2, 24.18.1
High CVE-2026-56848 node 22.23.1 22.23.2, 24.18.1, 26.5.1
High GHSA-rgw5-rvv9-x895 brace-expansion 5.0.7 5.0.9
High GHSA-mh99-v99m-4gvg brace-expansion 5.0.7 5.0.8
High GHSA-mwp4-54f8-5fhr ip-address 10.2.0 10.3.1
High CVE-2026-58043 node 22.23.1 22.23.2, 24.18.1, 26.5.1
Medium CVE-2026-58042 node 22.23.1 22.23.2, 24.18.1, 26.5.1
Medium CVE-2025-60876 busybox 1.37.0-r31 not specified
Medium CVE-2025-60876 busybox-binsh 1.37.0-r31 not specified
Medium CVE-2025-60876 ssl_client 1.37.0-r31 not specified
Medium CVE-2026-58041 node 22.23.1 22.23.2, 24.18.1, 26.5.1
Medium GHSA-4xrf-jv44-h6hh ip-address 10.2.0 10.2.2
Medium CVE-2026-58040 node 22.23.1 22.23.2, 24.18.1, 26.5.1
Medium GHSA-22jq-vg5j-6vgg ip-address 10.2.0 10.2.1
Medium CVE-2026-58055 nghttp2-libs 1.69.0-r0 not specified
Medium CVE-2026-58045 node 22.23.1 22.23.2, 24.18.1, 26.5.1
Medium GHSA-8xcm-r25x-g524 undici 6.27.0 6.28.0
Medium GHSA-v3r7-h72x-cjcm undici 6.27.0 6.28.0
Medium GHSA-m8rv-5g2x-5cg5 undici 6.27.0 6.28.0
Medium CVE-2026-56850 node 22.23.1 22.23.2, 24.18.1, 26.5.1
Medium GHSA-r292-9mhp-454m tar 7.5.19 7.5.21
Low CVE-2026-58044 node 22.23.1 22.23.2, 24.18.1, 26.5.1
Low CVE-2026-58039 node 22.23.1 22.23.2, 24.18.1, 26.5.1
Low CVE-2026-56847 node 22.23.1 22.23.2, 24.18.1, 26.5.1

License Violations

40 rejected/unknown licenses
Package Version License(s)
path-scurry 2.0.2 BlueOak-1.0.0
libncursesw 6.6_p20260516-r0 X11
ca-certificates-bundle 20260611-r0 MPL-2.0
apk-tools 3.0.6-r0 GPL-2.0-only
npm 11.18.0 Artistic-2.0
libstdc++ 15.2.0-r5 GPL-2.0-or-later, LGPL-2.1-or-later
libunistring 1.4.2-r0 LGPL-3.0-or-later, GPL-2.0-or-later
ncurses-terminfo-base 6.6_p20260516-r0 X11
spdx-license-ids 3.0.23 CC0-1.0
busybox-binsh 1.37.0-r31 GPL-2.0-only
zstd-libs 1.5.7-r2 GPL-2.0-or-later
awf-cli-proxy 1.0.0 no licenses found (first-party package — add license field)
glob 13.0.6 BlueOak-1.0.0
libcurl 8.21.0-r0 curl
zlib 1.3.2-r0 Zlib
libapk 3.0.6-r0 GPL-2.0-only
libgcc 15.2.0-r5 GPL-2.0-or-later, LGPL-2.1-or-later
ca-certificates 20260611-r0 MPL-2.0
busybox 1.37.0-r31 GPL-2.0-only
musl-utils 1.2.6-r2 GPL-2.0-or-later
curl 8.21.0-r0 curl
readline 8.3.3-r1 GPL-3.0-or-later
minimatch 10.2.5 BlueOak-1.0.0
minipass-flush 1.0.6 BlueOak-1.0.0
minipass 7.1.3 BlueOak-1.0.0
ssl_client 1.37.0-r31 GPL-2.0-only
qrcode-terminal 0.12.0 Apache 2.0
chownr 3.0.0 BlueOak-1.0.0
tar 7.5.19 BlueOak-1.0.0
scanelf 1.3.9-r1 GPL-2.0-only
lru-cache 11.5.1 BlueOak-1.0.0
common-ancestor-path 2.0.0 BlueOak-1.0.0
isexe 4.0.0 BlueOak-1.0.0
node 22.23.1 no licenses found
libidn2 2.3.8-r0 LGPL-3.0-or-later, GPL-2.0-or-later
bash 5.3.9-r1 GPL-3.0-or-later
spdx-exceptions 2.5.0 CC-BY-3.0
yallist 5.0.0 BlueOak-1.0.0
alpine-baselayout 3.7.2-r1 GPL-2.0-only
alpine-baselayout-data 3.7.2-r1 GPL-2.0-only

Generated by 🛡️ Daily Container Image Security Scan · auto · 327.5 AIC · ⌖ 10.6 AIC · ⊞ 6.5K ·

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions