Container Scan Findings
Scan date: 2026-07-23 | Tools: Syft 1.49.0 · Grype 0.116.0 · Grant 0.6.8
Grype DB: built 2026-07-22T07:06:24Z, schema v6.1.9, status valid
Image
| Field |
Value |
| Tag |
ghcr.io/github/gh-aw-firewall/agent:0.27.37 |
| Pinned digest |
sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 |
| Current digest |
sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 |
| Digest drift |
None |
Platform digests
| Platform |
Digest |
| linux/amd64 |
sha256:245d228c4d339eb78694682c28479e9e32bf29fcc7747c8b4e00b757fbe9851b |
| linux/arm64 |
sha256:81f01ad52af241e6f663f037a26f8e9233c82e9bd74dae5673755097d4e26307 |
Vulnerability Summary
| Total |
Critical |
Fixable |
| 1296 |
22 |
456 |
Vulnerabilities (linux/amd64 — notable Critical and High)
| Severity |
ID |
Package |
Installed |
Fixed In |
| Critical |
GO-2023-1703 |
stdlib |
go1.18, go1.18.1 |
*1.19.8, 1.20.3 |
| Critical |
GO-2023-1752 |
stdlib |
go1.18, go1.18.1 |
*1.19.9, 1.20.4 |
| Critical |
GO-2024-2887 |
stdlib |
go1.18, go1.18.1 |
*1.21.11, 1.22.4 |
| Critical |
GO-2025-3563 |
stdlib |
go1.18, go1.18.1 |
*1.23.8, 1.24.2 |
| Critical |
GO-2026-4337 |
stdlib |
go1.18, go1.18.1 |
*1.24.13, 1.25.7, 1.26.0-rc.3 |
| Critical |
GHSA-23hp-3jrh-7fpw |
tar |
7.5.11 |
7.5.19 |
| High (KEV) |
CVE-2023-44487 |
nodejs |
22.23.1-1nodesource1 |
won't fix |
| High |
GO-2024-2687 |
stdlib |
go1.18, go1.18.1 |
*1.21.9, 1.22.2 |
| High |
CVE-2026-45447 |
nodejs |
22.23.1-1nodesource1 |
won't fix |
| High |
GO-2022-0433 |
stdlib |
go1.18 |
1.17.9, *1.18.1 |
| High |
GO-2023-1571 |
stdlib |
go1.18, go1.18.1 |
*1.19.6, 1.20.1 |
| High |
GO-2023-2102 |
stdlib |
go1.18, go1.18.1 |
*1.20.10, 1.21.3 |
| High |
GO-2023-2185 |
stdlib |
go1.18, go1.18.1 |
*1.20.11, 1.21.4 |
| High |
GO-2026-4341 |
stdlib |
go1.18, go1.18.1 |
*1.24.12, 1.25.6 |
| Medium |
CVE-2023-50387 |
bind9-libs |
1:9.18.39-0ubuntu0.22.04.4 |
none |
| Medium |
CVE-2024-27983 |
nodejs |
22.23.1-1nodesource1 |
won't fix |
| Medium |
CVE-2023-50868 |
bind9-libs |
1:9.18.39-0ubuntu0.22.04.4 |
none |
Note: 1296 total vulnerabilities across both platforms (arm64 matches amd64). Only representative entries shown above; see grype-image-01-linux-amd64.txt and grype-image-01-linux-arm64.txt for full list.
License Compliance (Grant)
Policy: allow MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISC; require known license.
| Platform |
Catalogued |
Allowed |
Denied |
Non-SPDX |
| linux/amd64 |
418 |
187 |
220 |
95 |
| linux/arm64 |
similar |
— |
220 |
— |
Rejected license categories (amd64): GPL-1.0-only, GPL-1.0-or-later, GPL-2.0-only, GPL-2.0-or-later, GPL-3.0-only, GPL-3.0-or-later, LGPL-2.0-only, LGPL-2.1-only, AGPL variants, CC-BY-3.0, CC-BY-4.0, CC-BY-SA-3.0, CC0-1.0, MPL-2.0, Artistic, Artistic-2.0, BlueOak-1.0.0, Zlib, curl, and numerous LicenseRef-* non-SPDX identifiers.
2 packages have no license declared.
Operational Errors
None.
Remediation
- stdlib (go1.18/1.18.1): Rebuild image with Go ≥ 1.26.4. Multiple Critical CVEs are addressed in later releases.
- nodejs (22.23.1-1nodesource1): Several High/Medium CVEs marked "won't fix" by upstream — evaluate whether the nodejs deb package can be replaced or pinned to a version with fixes.
- tar (7.5.11 npm): Upgrade to ≥ 7.5.19 to fix GHSA-23hp-3jrh-7fpw (Critical).
- bind9-libs: No upstream fix available yet; monitor for security updates.
- License rejections: 220 packages include GPL, LGPL, CC, MPL, and other non-allowed licenses. Conduct a license review and replace or exempt packages as per policy.
Generated by 🛡️ Daily Container Image Security Scan · sonnet46 78.7 AIC · ⌖ 8.9 AIC · ⊞ 4.5K · ◷
Container Scan Findings
Scan date: 2026-07-23 | Tools: Syft 1.49.0 · Grype 0.116.0 · Grant 0.6.8
Grype DB: built 2026-07-22T07:06:24Z, schema v6.1.9, status valid
Image
ghcr.io/github/gh-aw-firewall/agent:0.27.37sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67Platform digests
sha256:245d228c4d339eb78694682c28479e9e32bf29fcc7747c8b4e00b757fbe9851bsha256:81f01ad52af241e6f663f037a26f8e9233c82e9bd74dae5673755097d4e26307Vulnerability Summary
Vulnerabilities (linux/amd64 — notable Critical and High)
License Compliance (Grant)
Policy: allow MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISC; require known license.
Rejected license categories (amd64): GPL-1.0-only, GPL-1.0-or-later, GPL-2.0-only, GPL-2.0-or-later, GPL-3.0-only, GPL-3.0-or-later, LGPL-2.0-only, LGPL-2.1-only, AGPL variants, CC-BY-3.0, CC-BY-4.0, CC-BY-SA-3.0, CC0-1.0, MPL-2.0, Artistic, Artistic-2.0, BlueOak-1.0.0, Zlib, curl, and numerous LicenseRef-* non-SPDX identifiers.
Operational Errors
None.
Remediation