Skip to content

[container-image-scan] Container findings for 0d35e8682845 #47472

Description

@github-actions

Container Scan Report

Scan date: 2026-07-23
Scanner versions: Syft 1.49.0 · Grype 0.116.0 · Grant 0.6.8
Grype DB: Schema v6.1.9, built 2026-07-22T07:06:24Z — status: valid


Image

Field Value
Image tag ghcr.io/github/gh-aw-firewall/agent:0.27.37
Pinned image ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67
Index digest sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67
Digest drift No

Platform digests

Platform Digest
linux/amd64 sha256:245d228c4d339eb78694682c28479e9e32bf29fcc7747c8b4e00b757fbe9851b
linux/arm64 sha256:81f01ad52af241e6f663f037a26f8e9233c82e9bd74dae5673755097d4e26307

Vulnerability Summary

Total: 1296 · Critical: 22 · Fixable: 456

Vulnerabilities are identical across amd64 and arm64 (same packages). Table lists amd64 scan findings.

Vulnerabilities (648 entries — click to expand)
Package Installed Fixed In Type Vulnerability Severity
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2023-44487 High
stdlib go1.18 1.21.9, 1.22.2 go-module GO-2024-2687 High
stdlib go1.18.1 1.21.9, 1.22.2 go-module GO-2024-2687 High
stdlib go1.18 1.19.8, 1.20.3 go-module GO-2023-1703 Critical
stdlib go1.18.1 1.19.8, 1.20.3 go-module GO-2023-1703 Critical
stdlib go1.18 1.21.11, 1.22.4 go-module GO-2024-2887 Critical
stdlib go1.18.1 1.21.11, 1.22.4 go-module GO-2024-2887 Critical
stdlib go1.18 1.19.9, 1.20.4 go-module GO-2023-1752 Critical
stdlib go1.18.1 1.19.9, 1.20.4 go-module GO-2023-1752 Critical
stdlib go1.18 1.24.13, 1.25.7 go-module GO-2026-4337 Critical
stdlib go1.18.1 1.24.13, 1.25.7 go-module GO-2026-4337 Critical
stdlib go1.18 1.23.8, 1.24.2 go-module GO-2025-3563 Critical
stdlib go1.18.1 1.23.8, 1.24.2 go-module GO-2025-3563 Critical
tar 7.5.11 7.5.19 npm GHSA-23hp-3jrh-7fpw Critical
bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb CVE-2023-50387 Medium
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2024-27983 Medium
bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb CVE-2023-50868 Medium
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2024-6119 Medium
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2025-15467 Medium
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2026-21710 Medium
bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb CVE-2024-12705 Medium
bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb CVE-2024-11187 Medium
stdlib go1.18 1.17.9, 1.18.1 go-module GO-2022-0433 High
bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb CVE-2025-8677 Medium
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2021-44532 Medium
stdlib go1.18 1.19.6, 1.20.1 go-module GO-2023-1571 High
stdlib go1.18.1 1.19.6, 1.20.1 go-module GO-2023-1571 High
stdlib go1.18 1.17.9, 1.18.1 go-module GO-2022-0435 High
stdlib go1.18 1.18.9, 1.19.4 go-module GO-2022-1144 Medium
stdlib go1.18.1 1.18.9, 1.19.4 go-module GO-2022-1144 Medium
stdlib go1.18 1.20.10, 1.21.3 go-module GO-2023-2102 High
stdlib go1.18.1 1.20.10, 1.21.3 go-module GO-2023-2102 High
bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb CVE-2024-0760 Medium
stdlib go1.18 1.20.11, 1.21.4 go-module GO-2023-2185 High
stdlib go1.18.1 1.20.11, 1.21.4 go-module GO-2023-2185 High
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2026-45447 High
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2023-3446 Low
stdlib go1.18 1.18.6, 1.19.1 go-module GO-2022-0969 High
stdlib go1.18.1 1.18.6, 1.19.1 go-module GO-2022-0969 High
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2025-59465 Medium
bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb CVE-2023-2828 Medium
stdlib go1.18 1.21.11, 1.22.4 go-module GO-2024-2887 Critical
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2024-9143 Low
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2025-55131 Medium
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2024-5535 Low
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2023-5363 Medium
stdlib go1.18 1.17.11, 1.18.3 go-module GO-2022-0477 High
stdlib go1.18.1 1.17.11, 1.18.3 go-module GO-2022-0477 High
stdlib go1.18 1.17.13, 1.18.5 go-module GO-2022-0537 High
stdlib go1.18.1 1.17.13, 1.18.5 go-module GO-2022-0537 High
stdlib go1.18 1.24.12, 1.25.6 go-module GO-2026-4341 High
stdlib go1.18.1 1.24.12, 1.25.6 go-module GO-2026-4341 High
stdlib go1.18 1.19.8, 1.20.3 go-module GO-2023-1704 High
stdlib go1.18.1 1.19.8, 1.20.3 go-module GO-2023-1704 High
stdlib go1.18 1.17.12, 1.18.4 go-module GO-2022-0521 High
stdlib go1.18.1 1.17.12, 1.18.4 go-module GO-2022-0521 High
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2026-48933 Medium
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2023-5678 Low
stdlib go1.18 1.17.10, 1.18.2 go-module GO-2022-0493 Medium
stdlib go1.18.1 1.17.10, 1.18.2 go-module GO-2022-0493 Medium
stdlib go1.18 1.17.11, 1.18.3 go-module GO-2022-0533 High
stdlib go1.18.1 1.17.11, 1.18.3 go-module GO-2022-0533 High
stdlib go1.18 1.19.6, 1.20.1 go-module GO-2023-1568 High
stdlib go1.18.1 1.19.6, 1.20.1 go-module GO-2023-1568 High
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2026-48618 Medium
stdlib go1.18 1.17.12, 1.18.4 go-module GO-2022-0527 High
stdlib go1.18.1 1.17.12, 1.18.4 go-module GO-2022-0527 High
stdlib go1.18 1.17.12, 1.18.4 go-module GO-2022-0522 High
stdlib go1.18 1.17.12, 1.18.4 go-module GO-2022-0523 High
stdlib go1.18.1 1.17.12, 1.18.4 go-module GO-2022-0522 High
stdlib go1.18.1 1.17.12, 1.18.4 go-module GO-2022-0523 High
stdlib go1.18 1.17.12, 1.18.4 go-module GO-2022-0524 High
stdlib go1.18.1 1.17.12, 1.18.4 go-module GO-2022-0524 High
stdlib go1.18 1.18.7, 1.19.2 go-module GO-2022-1037 High
stdlib go1.18.1 1.18.7, 1.19.2 go-module GO-2022-1037 High
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2019-1563 Low
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2022-40735 Medium
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2025-9231 Medium
stdlib go1.18 1.19.8, 1.20.3 go-module GO-2023-1705 High
stdlib go1.18.1 1.19.8, 1.20.3 go-module GO-2023-1705 High
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2023-0464 Low
stdlib go1.18 1.18.1 go-module GO-2022-0434 High
(and ~560 more entries — see full grype-image-01-linux-amd64.json for complete list)

Rejected Licenses (Grant)

Policy: Allow MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISC only.

Platform Packages cataloged Denied Denied licenses
linux/amd64 418 (407 evaluated) 220 GPL-2.0-only (51), GPL-2.0-or-later (44), LGPL-2.1-only (41), LGPL-2.1-or-later (29), GPL-3.0-or-later (29), GPL-3.0-only (28), LGPL-3.0-or-later (23), CC0-1.0 (19), non-SPDX hashes (95)
linux/arm64 418 (407 evaluated) 220 Same as amd64

Examples of denied packages: python3-minimal (non-SPDX), psmisc (GPL-2.0), libhogweed6 (GPL/LGPL composite), dpkg (GPL-2.0-or-later), libxau6 (non-SPDX hash), and 215 others.


Remediation

  • Go stdlib: Upgrade from go1.18 / go1.18.1 to ≥ go1.25.7 (or 1.26.4) to fix all Go-module CVEs including 22 critical entries.
  • nodejs: nodejs 22.23.1-1nodesource1 has no upstream fix for several CVEs (won't-fix); evaluate pinning a newer NodeSource release or switching base image.
  • bind9-libs: Upgrade to address CVE-2023-50387, CVE-2023-50868, and related DNS-related DoS issues.
  • tar (npm): Upgrade to ≥ 7.5.19 to fix critical GHSA-23hp-3jrh-7fpw.
  • License policy: 220 packages denied under the current allow-list (only MIT/Apache-2.0/BSD/ISC). Review whether GPL/LGPL/CC0 use is intentional and update policy or replace packages accordingly.
  • Rebuild the image with an updated Go toolchain and refreshed base packages.

Generated by 🛡️ Daily Container Image Security Scan · sonnet46 122.8 AIC · ⌖ 10 AIC · ⊞ 4.5K ·

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions