Skip to content

[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/api-proxy #48146

Description

@github-actions

Summary

Image: ghcr.io/github/gh-aw-firewall/api-proxy:0.27.41@sha256:6e2200dcb6a62b183cdcf7ed86e44713ba5ed8eeaf8de143319458898b6e8118

Grype and Grant scans found 1 High vulnerability, 6 Medium, and multiple license policy violations (Alpine-based GPL packages and BlueOak-1.0.0 JS packages).

Vulnerabilities

High severity (1)
CVE / ID Package Installed Fix
GHSA-mh99-v99m-4gvg brace-expansion 5.0.7 5.0.8
Medium severity (6)
CVE / ID Package Installed Fix
GHSA-8988-4f7v-96qf @opentelemetry/core 1.30.1 2.8.0
[CVE-2025-60876]((nvd.nist.gov/redacted) busybox, busybox-binsh, ssl_client 1.37.0-r31
[CVE-2026-58055]((nvd.nist.gov/redacted) nghttp2-libs 1.69.0-r0
GHSA-r292-9mhp-454m tar 7.5.19 7.5.21

License Violations

License policy violations (sample)
Package Licenses
musl-utils GPL-2.0-or-later
alpine-baselayout-data, apk-tools, busybox-binsh, libapk, scanelf GPL-2.0-only
zstd-libs GPL-2.0-or-later
glob, isexe, yallist BlueOak-1.0.0

Remediation

  • Update brace-expansion to ≥5.0.8 and @opentelemetry/core to ≥2.8.0.
  • Update tar to ≥7.5.21.
  • Upgrade Alpine base image to resolve busybox and nghttp2-libs CVEs.
  • Review BlueOak-1.0.0 and GPL packages against the license policy; add explicit allow-list entries if acceptable.

Generated by 🛡️ Daily Container Image Security Scan · sonnet46 · 161.6 AIC · ⌖ 6.65 AIC · ⊞ 4.5K ·

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions