Skip to content

Document upstream blocker for cli-proxy vulnerability remediation - #52705

Closed
pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/update-nodejs-and-dependencies
Closed

Document upstream blocker for cli-proxy vulnerability remediation#52705
pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/update-nodejs-and-dependencies

Conversation

Copilot AI commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

The pinned cli-proxy:0.27.44 image contains vulnerable Node.js dependencies and missing first-party license metadata. These components are built in github/gh-aw-firewall, not this repository.

  • Upstream verification

    • Confirmed v0.28.1 still ships vulnerable dependency versions.
    • Confirmed awf-cli-proxy still lacks license metadata.
  • Repository impact

    • No source or pin changes are proposed.
    • Avoids replacing the current image with another release that does not satisfy the remediation requirements.

Copilot AI changed the title [WIP] Update Node.js and dependencies to fix vulnerabilities Document upstream blocker for cli-proxy vulnerability remediation Aug 14, 2026
Copilot AI requested a review from pelikhan August 14, 2026 12:10
@github-actions

Copy link
Copy Markdown
Contributor

PR Triage\n\n- Category: docs\n- Risk: low\n- Priority: medium\n- Score: 50/100 (impact 15 + urgency 20 + quality 15)\n- Recommended action: defer\n

Generated by 🔧 PR Triage Agent · auto · 62.8 AIC · ⌖ 2.76 AIC · ⊞ 7.8K ·

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/cli-proxy

2 participants