Skip to content

[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/cli-proxy #48147

Description

@github-actions

Summary

Image: ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.41@sha256:5338ee1b80ebf194436d9368deb376296c09a833ca4d80293dee249f94c7ff73

Grype and Grant scans found 3 High vulnerabilities, 6 Medium, and multiple license policy violations.

Vulnerabilities

High severity (3)
CVE / ID Package Installed Fix
GO-2026-5970 golang.org/x/text v0.38.0 0.39.0
GHSA-mh99-v99m-4gvg brace-expansion 5.0.7 5.0.8
GHSA-hrxh-6v49-42gf google.golang.org/grpc v1.81.1 1.82.1
Medium severity (6)
CVE / ID Package Installed Fix
[CVE-2025-60876]((nvd.nist.gov/redacted) busybox, busybox-binsh, ssl_client 1.37.0-r31
GO-2026-5856 stdlib go1.26.4 1.26.5
[CVE-2026-58055]((nvd.nist.gov/redacted) nghttp2-libs 1.69.0-r0
GHSA-r292-9mhp-454m tar 7.5.19 7.5.21

License Violations

License policy violations for Alpine base packages (GPL-2.0) and BlueOak-1.0.0 JS packages (same pattern as api-proxy).

Remediation

  • Update golang.org/x/text to ≥0.39.0, google.golang.org/grpc to ≥1.82.1, brace-expansion to ≥5.0.8.
  • Update Go stdlib to ≥1.26.5; update tar to ≥7.5.21.
  • Upgrade Alpine base image.

Generated by 🛡️ Daily Container Image Security Scan · sonnet46 · 161.6 AIC · ⌖ 6.65 AIC · ⊞ 4.5K ·

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions