Conversation
Copilot
AI
changed the title
[WIP] Fix vulnerabilities in container image for gh-aw-firewall/agent
Document blocker for gh-aw-firewall/agent scan remediation
Aug 11, 2026
Contributor
|
Thanks for creating this blocker documentation! 🎯 This PR clearly captures an upstream-blocked remediation scenario for the gh-aw-firewall agent container image CVEs. A couple of things to get this ready:
The description is excellent — it sets clear expectations for the follow-up work once upstream publishes a patched image. Once the implementation is in place, this should be good to go.
|
github-actions
Bot
deleted the
copilot/container-image-scan-resolve-findings
branch
August 19, 2026 02:25
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
ghcr.io/github/gh-aw-firewall/agent:0.27.44is currently flagged with high-severity Node CVEs, but there is no newer upstream AWF release/tag or rebuilt digest available to consume fromgh-aw. This PR captures that remediation is upstream-blocked rather than applying a no-op pin churn.Problem context
0.27.44@sha256:0d7277…), plus lower-severity Ubuntu package findings.Change scope in this PR
pkg/actionpins/data/action_pins.json,.github/aw/actions-lock.json, andDefaultFirewallVersion).Reason for no pin bump
github/gh-aw-firewallrelease/tag is stillv0.27.44.agent:0.27.44remains unchanged, so any in-repo edit would not remediate the reported CVEs.Planned follow-up once upstream publishes patched image
DefaultFirewallVersion.