Summary
Image: ghcr.io/github/gh-aw-firewall/api-proxy:0.27.41@sha256:6e2200dcb6a62b183cdcf7ed86e44713ba5ed8eeaf8de143319458898b6e8118
Grype and Grant scans found 1 High vulnerability, 6 Medium, and multiple license policy violations (Alpine-based GPL packages and BlueOak-1.0.0 JS packages).
Vulnerabilities
High severity (1)
Medium severity (6)
License Violations
License policy violations (sample)
| Package |
Licenses |
| musl-utils |
GPL-2.0-or-later |
| alpine-baselayout-data, apk-tools, busybox-binsh, libapk, scanelf |
GPL-2.0-only |
| zstd-libs |
GPL-2.0-or-later |
| glob, isexe, yallist |
BlueOak-1.0.0 |
Remediation
- Update
brace-expansion to ≥5.0.8 and @opentelemetry/core to ≥2.8.0.
- Update
tar to ≥7.5.21.
- Upgrade Alpine base image to resolve busybox and nghttp2-libs CVEs.
- Review BlueOak-1.0.0 and GPL packages against the license policy; add explicit allow-list entries if acceptable.
Generated by 🛡️ Daily Container Image Security Scan · sonnet46 · 161.6 AIC · ⌖ 6.65 AIC · ⊞ 4.5K · ◷
Summary
Image:
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.41@sha256:6e2200dcb6a62b183cdcf7ed86e44713ba5ed8eeaf8de143319458898b6e8118Grype and Grant scans found 1 High vulnerability, 6 Medium, and multiple license policy violations (Alpine-based GPL packages and BlueOak-1.0.0 JS packages).
Vulnerabilities
High severity (1)
Medium severity (6)
@opentelemetry/coreLicense Violations
License policy violations (sample)
Remediation
brace-expansionto ≥5.0.8 and@opentelemetry/coreto ≥2.8.0.tarto ≥7.5.21.