Container Scan Report
Scan date: 2026-07-23
Scanner versions: Syft 1.49.0 · Grype 0.116.0 · Grant 0.6.8
Grype DB: Schema v6.1.9, built 2026-07-22T07:06:24Z — status: valid
Image
| Field |
Value |
| Image tag |
ghcr.io/github/gh-aw-firewall/agent:0.27.37 |
| Pinned image |
ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 |
| Index digest |
sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 |
| Digest drift |
No |
Platform digests
| Platform |
Digest |
| linux/amd64 |
sha256:245d228c4d339eb78694682c28479e9e32bf29fcc7747c8b4e00b757fbe9851b |
| linux/arm64 |
sha256:81f01ad52af241e6f663f037a26f8e9233c82e9bd74dae5673755097d4e26307 |
Vulnerability Summary
Total: 1296 · Critical: 22 · Fixable: 456
Vulnerabilities are identical across amd64 and arm64 (same packages). Table lists amd64 scan findings.
Vulnerabilities (648 entries — click to expand)
| Package |
Installed |
Fixed In |
Type |
Vulnerability |
Severity |
| nodejs |
22.23.1-1nodesource1 |
(won't fix) |
deb |
CVE-2023-44487 |
High |
| stdlib |
go1.18 |
1.21.9, 1.22.2 |
go-module |
GO-2024-2687 |
High |
| stdlib |
go1.18.1 |
1.21.9, 1.22.2 |
go-module |
GO-2024-2687 |
High |
| stdlib |
go1.18 |
1.19.8, 1.20.3 |
go-module |
GO-2023-1703 |
Critical |
| stdlib |
go1.18.1 |
1.19.8, 1.20.3 |
go-module |
GO-2023-1703 |
Critical |
| stdlib |
go1.18 |
1.21.11, 1.22.4 |
go-module |
GO-2024-2887 |
Critical |
| stdlib |
go1.18.1 |
1.21.11, 1.22.4 |
go-module |
GO-2024-2887 |
Critical |
| stdlib |
go1.18 |
1.19.9, 1.20.4 |
go-module |
GO-2023-1752 |
Critical |
| stdlib |
go1.18.1 |
1.19.9, 1.20.4 |
go-module |
GO-2023-1752 |
Critical |
| stdlib |
go1.18 |
1.24.13, 1.25.7 |
go-module |
GO-2026-4337 |
Critical |
| stdlib |
go1.18.1 |
1.24.13, 1.25.7 |
go-module |
GO-2026-4337 |
Critical |
| stdlib |
go1.18 |
1.23.8, 1.24.2 |
go-module |
GO-2025-3563 |
Critical |
| stdlib |
go1.18.1 |
1.23.8, 1.24.2 |
go-module |
GO-2025-3563 |
Critical |
| tar |
7.5.11 |
7.5.19 |
npm |
GHSA-23hp-3jrh-7fpw |
Critical |
| bind9-libs |
1:9.18.39-0ubuntu0.22.04.4 |
— |
deb |
CVE-2023-50387 |
Medium |
| nodejs |
22.23.1-1nodesource1 |
(won't fix) |
deb |
CVE-2024-27983 |
Medium |
| bind9-libs |
1:9.18.39-0ubuntu0.22.04.4 |
— |
deb |
CVE-2023-50868 |
Medium |
| nodejs |
22.23.1-1nodesource1 |
(won't fix) |
deb |
CVE-2024-6119 |
Medium |
| nodejs |
22.23.1-1nodesource1 |
(won't fix) |
deb |
CVE-2025-15467 |
Medium |
| nodejs |
22.23.1-1nodesource1 |
(won't fix) |
deb |
CVE-2026-21710 |
Medium |
| bind9-libs |
1:9.18.39-0ubuntu0.22.04.4 |
— |
deb |
CVE-2024-12705 |
Medium |
| bind9-libs |
1:9.18.39-0ubuntu0.22.04.4 |
— |
deb |
CVE-2024-11187 |
Medium |
| stdlib |
go1.18 |
1.17.9, 1.18.1 |
go-module |
GO-2022-0433 |
High |
| bind9-libs |
1:9.18.39-0ubuntu0.22.04.4 |
— |
deb |
CVE-2025-8677 |
Medium |
| nodejs |
22.23.1-1nodesource1 |
(won't fix) |
deb |
CVE-2021-44532 |
Medium |
| stdlib |
go1.18 |
1.19.6, 1.20.1 |
go-module |
GO-2023-1571 |
High |
| stdlib |
go1.18.1 |
1.19.6, 1.20.1 |
go-module |
GO-2023-1571 |
High |
| stdlib |
go1.18 |
1.17.9, 1.18.1 |
go-module |
GO-2022-0435 |
High |
| stdlib |
go1.18 |
1.18.9, 1.19.4 |
go-module |
GO-2022-1144 |
Medium |
| stdlib |
go1.18.1 |
1.18.9, 1.19.4 |
go-module |
GO-2022-1144 |
Medium |
| stdlib |
go1.18 |
1.20.10, 1.21.3 |
go-module |
GO-2023-2102 |
High |
| stdlib |
go1.18.1 |
1.20.10, 1.21.3 |
go-module |
GO-2023-2102 |
High |
| bind9-libs |
1:9.18.39-0ubuntu0.22.04.4 |
— |
deb |
CVE-2024-0760 |
Medium |
| stdlib |
go1.18 |
1.20.11, 1.21.4 |
go-module |
GO-2023-2185 |
High |
| stdlib |
go1.18.1 |
1.20.11, 1.21.4 |
go-module |
GO-2023-2185 |
High |
| nodejs |
22.23.1-1nodesource1 |
(won't fix) |
deb |
CVE-2026-45447 |
High |
| nodejs |
22.23.1-1nodesource1 |
(won't fix) |
deb |
CVE-2023-3446 |
Low |
| stdlib |
go1.18 |
1.18.6, 1.19.1 |
go-module |
GO-2022-0969 |
High |
| stdlib |
go1.18.1 |
1.18.6, 1.19.1 |
go-module |
GO-2022-0969 |
High |
| nodejs |
22.23.1-1nodesource1 |
(won't fix) |
deb |
CVE-2025-59465 |
Medium |
| bind9-libs |
1:9.18.39-0ubuntu0.22.04.4 |
— |
deb |
CVE-2023-2828 |
Medium |
| stdlib |
go1.18 |
1.21.11, 1.22.4 |
go-module |
GO-2024-2887 |
Critical |
| nodejs |
22.23.1-1nodesource1 |
(won't fix) |
deb |
CVE-2024-9143 |
Low |
| nodejs |
22.23.1-1nodesource1 |
(won't fix) |
deb |
CVE-2025-55131 |
Medium |
| nodejs |
22.23.1-1nodesource1 |
(won't fix) |
deb |
CVE-2024-5535 |
Low |
| nodejs |
22.23.1-1nodesource1 |
(won't fix) |
deb |
CVE-2023-5363 |
Medium |
| stdlib |
go1.18 |
1.17.11, 1.18.3 |
go-module |
GO-2022-0477 |
High |
| stdlib |
go1.18.1 |
1.17.11, 1.18.3 |
go-module |
GO-2022-0477 |
High |
| stdlib |
go1.18 |
1.17.13, 1.18.5 |
go-module |
GO-2022-0537 |
High |
| stdlib |
go1.18.1 |
1.17.13, 1.18.5 |
go-module |
GO-2022-0537 |
High |
| stdlib |
go1.18 |
1.24.12, 1.25.6 |
go-module |
GO-2026-4341 |
High |
| stdlib |
go1.18.1 |
1.24.12, 1.25.6 |
go-module |
GO-2026-4341 |
High |
| stdlib |
go1.18 |
1.19.8, 1.20.3 |
go-module |
GO-2023-1704 |
High |
| stdlib |
go1.18.1 |
1.19.8, 1.20.3 |
go-module |
GO-2023-1704 |
High |
| stdlib |
go1.18 |
1.17.12, 1.18.4 |
go-module |
GO-2022-0521 |
High |
| stdlib |
go1.18.1 |
1.17.12, 1.18.4 |
go-module |
GO-2022-0521 |
High |
| nodejs |
22.23.1-1nodesource1 |
(won't fix) |
deb |
CVE-2026-48933 |
Medium |
| nodejs |
22.23.1-1nodesource1 |
(won't fix) |
deb |
CVE-2023-5678 |
Low |
| stdlib |
go1.18 |
1.17.10, 1.18.2 |
go-module |
GO-2022-0493 |
Medium |
| stdlib |
go1.18.1 |
1.17.10, 1.18.2 |
go-module |
GO-2022-0493 |
Medium |
| stdlib |
go1.18 |
1.17.11, 1.18.3 |
go-module |
GO-2022-0533 |
High |
| stdlib |
go1.18.1 |
1.17.11, 1.18.3 |
go-module |
GO-2022-0533 |
High |
| stdlib |
go1.18 |
1.19.6, 1.20.1 |
go-module |
GO-2023-1568 |
High |
| stdlib |
go1.18.1 |
1.19.6, 1.20.1 |
go-module |
GO-2023-1568 |
High |
| nodejs |
22.23.1-1nodesource1 |
(won't fix) |
deb |
CVE-2026-48618 |
Medium |
| stdlib |
go1.18 |
1.17.12, 1.18.4 |
go-module |
GO-2022-0527 |
High |
| stdlib |
go1.18.1 |
1.17.12, 1.18.4 |
go-module |
GO-2022-0527 |
High |
| stdlib |
go1.18 |
1.17.12, 1.18.4 |
go-module |
GO-2022-0522 |
High |
| stdlib |
go1.18 |
1.17.12, 1.18.4 |
go-module |
GO-2022-0523 |
High |
| stdlib |
go1.18.1 |
1.17.12, 1.18.4 |
go-module |
GO-2022-0522 |
High |
| stdlib |
go1.18.1 |
1.17.12, 1.18.4 |
go-module |
GO-2022-0523 |
High |
| stdlib |
go1.18 |
1.17.12, 1.18.4 |
go-module |
GO-2022-0524 |
High |
| stdlib |
go1.18.1 |
1.17.12, 1.18.4 |
go-module |
GO-2022-0524 |
High |
| stdlib |
go1.18 |
1.18.7, 1.19.2 |
go-module |
GO-2022-1037 |
High |
| stdlib |
go1.18.1 |
1.18.7, 1.19.2 |
go-module |
GO-2022-1037 |
High |
| nodejs |
22.23.1-1nodesource1 |
(won't fix) |
deb |
CVE-2019-1563 |
Low |
| nodejs |
22.23.1-1nodesource1 |
(won't fix) |
deb |
CVE-2022-40735 |
Medium |
| nodejs |
22.23.1-1nodesource1 |
(won't fix) |
deb |
CVE-2025-9231 |
Medium |
| stdlib |
go1.18 |
1.19.8, 1.20.3 |
go-module |
GO-2023-1705 |
High |
| stdlib |
go1.18.1 |
1.19.8, 1.20.3 |
go-module |
GO-2023-1705 |
High |
| nodejs |
22.23.1-1nodesource1 |
(won't fix) |
deb |
CVE-2023-0464 |
Low |
| stdlib |
go1.18 |
1.18.1 |
go-module |
GO-2022-0434 |
High |
| (and ~560 more entries — see full grype-image-01-linux-amd64.json for complete list) |
|
|
|
|
|
Rejected Licenses (Grant)
Policy: Allow MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISC only.
| Platform |
Packages cataloged |
Denied |
Denied licenses |
| linux/amd64 |
418 (407 evaluated) |
220 |
GPL-2.0-only (51), GPL-2.0-or-later (44), LGPL-2.1-only (41), LGPL-2.1-or-later (29), GPL-3.0-or-later (29), GPL-3.0-only (28), LGPL-3.0-or-later (23), CC0-1.0 (19), non-SPDX hashes (95) |
| linux/arm64 |
418 (407 evaluated) |
220 |
Same as amd64 |
Examples of denied packages: python3-minimal (non-SPDX), psmisc (GPL-2.0), libhogweed6 (GPL/LGPL composite), dpkg (GPL-2.0-or-later), libxau6 (non-SPDX hash), and 215 others.
Remediation
- Go stdlib: Upgrade from
go1.18 / go1.18.1 to ≥ go1.25.7 (or 1.26.4) to fix all Go-module CVEs including 22 critical entries.
- nodejs:
nodejs 22.23.1-1nodesource1 has no upstream fix for several CVEs (won't-fix); evaluate pinning a newer NodeSource release or switching base image.
- bind9-libs: Upgrade to address CVE-2023-50387, CVE-2023-50868, and related DNS-related DoS issues.
- tar (npm): Upgrade to ≥ 7.5.19 to fix critical GHSA-23hp-3jrh-7fpw.
- License policy: 220 packages denied under the current allow-list (only MIT/Apache-2.0/BSD/ISC). Review whether GPL/LGPL/CC0 use is intentional and update policy or replace packages accordingly.
- Rebuild the image with an updated Go toolchain and refreshed base packages.
Generated by 🛡️ Daily Container Image Security Scan · sonnet46 122.8 AIC · ⌖ 10 AIC · ⊞ 4.5K · ◷
Container Scan Report
Scan date: 2026-07-23
Scanner versions: Syft 1.49.0 · Grype 0.116.0 · Grant 0.6.8
Grype DB: Schema v6.1.9, built 2026-07-22T07:06:24Z — status: valid
Image
ghcr.io/github/gh-aw-firewall/agent:0.27.37ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67Platform digests
sha256:245d228c4d339eb78694682c28479e9e32bf29fcc7747c8b4e00b757fbe9851bsha256:81f01ad52af241e6f663f037a26f8e9233c82e9bd74dae5673755097d4e26307Vulnerability Summary
Total: 1296 · Critical: 22 · Fixable: 456
Vulnerabilities are identical across amd64 and arm64 (same packages). Table lists amd64 scan findings.
Vulnerabilities (648 entries — click to expand)
Rejected Licenses (Grant)
Policy: Allow MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISC only.
Examples of denied packages: python3-minimal (non-SPDX), psmisc (GPL-2.0), libhogweed6 (GPL/LGPL composite), dpkg (GPL-2.0-or-later), libxau6 (non-SPDX hash), and 215 others.
Remediation
go1.18/go1.18.1to ≥go1.25.7(or1.26.4) to fix all Go-module CVEs including 22 critical entries.nodejs 22.23.1-1nodesource1has no upstream fix for several CVEs (won't-fix); evaluate pinning a newer NodeSource release or switching base image.