Skip to content

[WIP] Fix vulnerabilities and license violations in container image - #49852

Closed
pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/container-image-scan-fix-vulnerabilities-41a62874-02cb-4591-adbe-2fb14ea19e87
Closed

pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/container-image-scan-fix-vulnerabilities-41a62874-02cb-4591-adbe-2fb14ea19e87

Conversation

Copilot AI commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Thanks for asking me to work on this. I will get started on it and keep this PR's description up to date as I form a plan and make progress.


This section details on the original issue you should resolve

<issue_title>[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/cli-proxy</issue_title>
<issue_description>### Summary

Image ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.43 was scanned by Syft, Grype, and Grant.

  • Vulnerabilities: 9 total — 0 Critical, 3 High, 6 Medium
  • License violations: 40 packages flagged by policy

Image Reference

ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.43@sha256:65c45ea2967984d0024f3df61bc71335658a77ede96c8d9665da7a5f33a795ab

Vulnerabilities

9 vulnerabilities (0 Critical, 3 High, 6 Medium, 0 Low, 0 Negligible)
error: [High] GHSA-hrxh-6v49-42gf: google.golang.org/grpc@v1.81.1 (fix: 1.82.1) (https://github.com/advisories/GHSA-hrxh-6v49-42gf)
error: [High] GHSA-mh99-v99m-4gvg: brace-expansion@5.0.7 (fix: 5.0.8) (https://github.com/advisories/GHSA-mh99-v99m-4gvg)
error: [High] GO-2026-5970: golang.org/x/text@v0.38.0 (fix: 0.39.0) (https://go.dev/issue/80142)
warning: [Medium] CVE-2025-60876: busybox-binsh@1.37.0-r31 ((nvd.nist.gov/redacted)
warning: [Medium] CVE-2025-60876: busybox@1.37.0-r31 ((nvd.nist.gov/redacted)
warning: [Medium] CVE-2025-60876: ssl_client@1.37.0-r31 ((nvd.nist.gov/redacted)
warning: [Medium] CVE-2026-58055: nghttp2-libs@1.69.0-r0 ((nvd.nist.gov/redacted)
warning: [Medium] GHSA-r292-9mhp-454m: tar@7.5.19 (fix: 7.5.21) (https://github.com/advisories/GHSA-r292-9mhp-454m)
warning: [Medium] GO-2026-5856: stdlib@go1.26.4 (fix: 1.25.12, 1.26.5, 1.27.0-rc.2) (https://go.dev/cl/775960)

License Violations

40 packages flagged by license policy
alpine-baselayout-data@3.7.2-r1 (GPL-2.0-only)
alpine-baselayout@3.7.2-r1 (GPL-2.0-only)
apk-tools@3.0.6-r0 (GPL-2.0-only)
awf-cli-proxy@1.0.0 (no licenses found)
bash@5.3.9-r1 (GPL-3.0-or-later)
busybox-binsh@1.37.0-r31 (GPL-2.0-only)
busybox@1.37.0-r31 (GPL-2.0-only)
ca-certificates-bundle@20260611-r0 (MPL-2.0)
ca-certificates@20260611-r0 (MPL-2.0)
chownr@3.0.0 (BlueOak-1.0.0)
common-ancestor-path@2.0.0 (BlueOak-1.0.0)
curl@8.21.0-r0 (curl)
glob@13.0.6 (BlueOak-1.0.0)
isexe@4.0.0 (BlueOak-1.0.0)
libapk@3.0.6-r0 (GPL-2.0-only)
libcurl@8.21.0-r0 (curl)
libgcc@15.2.0-r5 (GPL-2.0-or-later, LGPL-2.1-or-later)
libidn2@2.3.8-r0 (GPL-2.0-or-later, LGPL-3.0-or-later)
libncursesw@6.6_p20260516-r0 (X11)
libstdc++`@15`.2.0-r5 (GPL-2.0-or-later, LGPL-2.1-or-later)
libunistring@1.4.2-r0 (GPL-2.0-or-later, LGPL-3.0-or-later)
lru-cache@11.5.1 (BlueOak-1.0.0)
minimatch@10.2.5 (BlueOak-1.0.0)
minipass-flush@1.0.6 (BlueOak-1.0.0)
minipass@7.1.3 (BlueOak-1.0.0)
musl-utils@1.2.6-r2 (GPL-2.0-or-later)
ncurses-terminfo-base@6.6_p20260516-r0 (X11)
node@22.23.1 (no licenses found)
npm@11.18.0 (Artistic-2.0)
path-scurry@2.0.2 (BlueOak-1.0.0)
qrcode-terminal@0.12.0 (Apache 2.0)
readline@8.3.3-r1 (GPL-3.0-or-later)
scanelf@1.3.9-r1 (GPL-2.0-only)
spdx-exceptions@2.5.0 (CC-BY-3.0)
spdx-license-ids@3.0.23 (CC0-1.0)
ssl_client@1.37.0-r31 (GPL-2.0-only)
tar@7.5.19 (BlueOak-1.0.0)
yallist@5.0.0 (BlueOak-1.0.0)
zlib@1.3.2-r0 (Zlib)
zstd-libs@1.5.7-r2 (GPL-2.0-or-later)

Remediation

  • Update google.golang.org/grpc to >=1.82.1 (GHSA-hrxh-6v49-42gf, High) and brace-expansion to >=5.0.8 (GHSA-mh99-v99m-4gvg, High).
  • Update Go toolchain/golang.org/x/text to >=0.39.0 (GO-2026-5970, High).
  • Rebase on a newer Alpine release for patched busybox/ssl_client (CVE-2025-60876) and nghttp2-libs (CVE-2026-58055); bump stdlib per GO-2026-5856 and tar to >=7.5.21.
  • Review GPL-2.0/3.0, LGPL, MPL-2.0, X11, Artistic-2.0, and BlueOak-1.0.0 licensed packages against license policy; most are Alpine base-layer or npm transitive dependencies.

Generated by 🛡️ Daily Container Image Security Scan · auto · 268.4 AIC · ⌖ 9.03 AIC · ⊞ 6.3K · ◷

Comments on the Issue (you are @copilot in this section)

@pelikhan pelikhan closed this Aug 2, 2026
Copilot stopped work on behalf of pelikhan due to an error August 2, 2026 21:00
Copilot AI requested a review from pelikhan August 2, 2026 21:00
@github-actions
github-actions Bot deleted the copilot/container-image-scan-fix-vulnerabilities-41a62874-02cb-4591-adbe-2fb14ea19e87 branch August 10, 2026 02:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/cli-proxy

2 participants