Skip to content

[container-image-scan] Container findings for 0d35e8682845 #47504

Description

@github-actions

Container Scan Findings

Scan date: 2026-07-23 | Tools: Syft 1.49.0 · Grype 0.116.0 · Grant 0.6.8
Grype DB: built 2026-07-22T07:06:24Z, schema v6.1.9, status valid


Image

Field Value
Tag ghcr.io/github/gh-aw-firewall/agent:0.27.37
Pinned digest sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67
Current digest sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67
Digest drift None

Platform digests

Platform Digest
linux/amd64 sha256:245d228c4d339eb78694682c28479e9e32bf29fcc7747c8b4e00b757fbe9851b
linux/arm64 sha256:81f01ad52af241e6f663f037a26f8e9233c82e9bd74dae5673755097d4e26307

Vulnerability Summary

Total Critical Fixable
1296 22 456

Vulnerabilities (linux/amd64 — notable Critical and High)

Severity ID Package Installed Fixed In
Critical GO-2023-1703 stdlib go1.18, go1.18.1 *1.19.8, 1.20.3
Critical GO-2023-1752 stdlib go1.18, go1.18.1 *1.19.9, 1.20.4
Critical GO-2024-2887 stdlib go1.18, go1.18.1 *1.21.11, 1.22.4
Critical GO-2025-3563 stdlib go1.18, go1.18.1 *1.23.8, 1.24.2
Critical GO-2026-4337 stdlib go1.18, go1.18.1 *1.24.13, 1.25.7, 1.26.0-rc.3
Critical GHSA-23hp-3jrh-7fpw tar 7.5.11 7.5.19
High (KEV) CVE-2023-44487 nodejs 22.23.1-1nodesource1 won't fix
High GO-2024-2687 stdlib go1.18, go1.18.1 *1.21.9, 1.22.2
High CVE-2026-45447 nodejs 22.23.1-1nodesource1 won't fix
High GO-2022-0433 stdlib go1.18 1.17.9, *1.18.1
High GO-2023-1571 stdlib go1.18, go1.18.1 *1.19.6, 1.20.1
High GO-2023-2102 stdlib go1.18, go1.18.1 *1.20.10, 1.21.3
High GO-2023-2185 stdlib go1.18, go1.18.1 *1.20.11, 1.21.4
High GO-2026-4341 stdlib go1.18, go1.18.1 *1.24.12, 1.25.6
Medium CVE-2023-50387 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 none
Medium CVE-2024-27983 nodejs 22.23.1-1nodesource1 won't fix
Medium CVE-2023-50868 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 none

Note: 1296 total vulnerabilities across both platforms (arm64 matches amd64). Only representative entries shown above; see grype-image-01-linux-amd64.txt and grype-image-01-linux-arm64.txt for full list.


License Compliance (Grant)

Policy: allow MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISC; require known license.

Platform Catalogued Allowed Denied Non-SPDX
linux/amd64 418 187 220 95
linux/arm64 similar 220

Rejected license categories (amd64): GPL-1.0-only, GPL-1.0-or-later, GPL-2.0-only, GPL-2.0-or-later, GPL-3.0-only, GPL-3.0-or-later, LGPL-2.0-only, LGPL-2.1-only, AGPL variants, CC-BY-3.0, CC-BY-4.0, CC-BY-SA-3.0, CC0-1.0, MPL-2.0, Artistic, Artistic-2.0, BlueOak-1.0.0, Zlib, curl, and numerous LicenseRef-* non-SPDX identifiers.

2 packages have no license declared.


Operational Errors

None.


Remediation

  • stdlib (go1.18/1.18.1): Rebuild image with Go ≥ 1.26.4. Multiple Critical CVEs are addressed in later releases.
  • nodejs (22.23.1-1nodesource1): Several High/Medium CVEs marked "won't fix" by upstream — evaluate whether the nodejs deb package can be replaced or pinned to a version with fixes.
  • tar (7.5.11 npm): Upgrade to ≥ 7.5.19 to fix GHSA-23hp-3jrh-7fpw (Critical).
  • bind9-libs: No upstream fix available yet; monitor for security updates.
  • License rejections: 220 packages include GPL, LGPL, CC, MPL, and other non-allowed licenses. Conduct a license review and replace or exempt packages as per policy.

Generated by 🛡️ Daily Container Image Security Scan · sonnet46 78.7 AIC · ⌖ 8.9 AIC · ⊞ 4.5K ·

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions