Skip to content

[container-image-scan] Container findings for node:lts-alpine #49518

Description

@github-actions

Summary

Image: node:lts-alpine
Pinned reference: node:lts-alpine@sha256:a0b9bf06e4e6193cf7a0f58816cc935ff8c2a908f81e6f1a95432d679c54fbfd

  • Vulnerabilities: 15 total — Critical: 1, High: 4, Medium: 8, Low: 2, Negligible: 0, Unknown: 0
  • License policy violations: 29

Remediation

  • Rebuild/update the image to pull in patched packages for the vulnerabilities listed below (fixed versions shown where available).
  • Review the licenses listed below against policy; consider replacing, removing, or granting an exception for flagged packages.
  • Re-run the scan after remediation to confirm the findings are resolved.

Critical & High severity vulnerabilities

[Critical] GHSA-23hp-3jrh-7fpw: tar@7.5.15 (fix: 7.5.19) (https://github.com/advisories/GHSA-23hp-3jrh-7fpw)
[High] GHSA-3jxr-9vmj-r5cp: brace-expansion@5.0.6 (fix: 5.0.7) (https://github.com/advisories/GHSA-3jxr-9vmj-r5cp)
[High] GHSA-8x88-c5mf-7j5w: tar@7.5.15 (fix: 7.5.18) (https://github.com/advisories/GHSA-8x88-c5mf-7j5w)
[High] GHSA-mh99-v99m-4gvg: brace-expansion@5.0.6 (fix: 5.0.8) (https://github.com/advisories/GHSA-mh99-v99m-4gvg)
[High] GHSA-vxpw-j846-p89q: undici@6.26.0 (fix: 6.27.0) (https://github.com/advisories/GHSA-vxpw-j846-p89q)
Medium / Low / Negligible / Unknown vulnerabilities (10 findings, 10 unique)
[Low] GHSA-35p6-xmwp-9g52: undici@6.26.0 (fix: 6.27.0) (https://github.com/advisories/GHSA-35p6-xmwp-9g52)
[Low] GHSA-g8m3-5g58-fq7m: undici@6.26.0 (fix: 6.27.0) (https://github.com/advisories/GHSA-g8m3-5g58-fq7m)
[Medium] CVE-2025-60876: busybox-binsh@1.37.0-r31 ((nvd.nist.gov/redacted)
[Medium] CVE-2025-60876: busybox@1.37.0-r31 ((nvd.nist.gov/redacted)
[Medium] CVE-2025-60876: ssl_client@1.37.0-r31 ((nvd.nist.gov/redacted)
[Medium] GHSA-gvwx-54wh-qm9j: tar@7.5.15 (fix: 7.5.17) (https://github.com/advisories/GHSA-gvwx-54wh-qm9j)
[Medium] GHSA-p88m-4jfj-68fv: undici@6.26.0 (fix: 6.27.0) (https://github.com/advisories/GHSA-p88m-4jfj-68fv)
[Medium] GHSA-r292-9mhp-454m: tar@7.5.15 (fix: 7.5.21) (https://github.com/advisories/GHSA-r292-9mhp-454m)
[Medium] GHSA-vmf3-w455-68vh: tar@7.5.15 (fix: 7.5.16) (https://github.com/advisories/GHSA-vmf3-w455-68vh)
[Medium] GHSA-w8wr-v893-vjvp: tar@7.5.15 (fix: 7.5.18) (https://github.com/advisories/GHSA-w8wr-v893-vjvp)
License policy violations (29 findings, 29 unique)
alpine-baselayout-data@3.7.2-r1 (GPL-2.0-only)
alpine-baselayout@3.7.2-r1 (GPL-2.0-only)
apk-tools@3.0.6-r0 (GPL-2.0-only)
busybox-binsh@1.37.0-r31 (GPL-2.0-only)
busybox@1.37.0-r31 (GPL-2.0-only)
ca-certificates-bundle@20260611-r0 (MPL-2.0)
chownr@3.0.0 (BlueOak-1.0.0)
common-ancestor-path@2.0.0 (BlueOak-1.0.0)
glob@13.0.6 (BlueOak-1.0.0)
isexe@4.0.0 (BlueOak-1.0.0)
libapk@3.0.6-r0 (GPL-2.0-only)
libgcc@15.2.0-r5 (GPL-2.0-or-later, LGPL-2.1-or-later)
libstdc++`@15`.2.0-r5 (LGPL-2.1-or-later, GPL-2.0-or-later)
lru-cache@11.5.1 (BlueOak-1.0.0)
minimatch@10.2.5 (BlueOak-1.0.0)
minipass-flush@1.0.6 (BlueOak-1.0.0)
minipass@7.1.3 (BlueOak-1.0.0)
musl-utils@1.2.6-r2 (GPL-2.0-or-later)
node@24.18.0 (no licenses found)
npm@11.16.0 (Artistic-2.0)
path-scurry@2.0.2 (BlueOak-1.0.0)
qrcode-terminal@0.12.0 (Apache 2.0)
scanelf@1.3.9-r1 (GPL-2.0-only)
spdx-exceptions@2.5.0 (CC-BY-3.0)
spdx-license-ids@3.0.23 (CC0-1.0)
ssl_client@1.37.0-r31 (GPL-2.0-only)
tar@7.5.15 (BlueOak-1.0.0)
yallist@5.0.0 (BlueOak-1.0.0)
zlib@1.3.2-r0 (Zlib)

Generated by 🛡️ Daily Container Image Security Scan · auto · 285.1 AIC · ⌖ 8.51 AIC · ⊞ 6.3K ·

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions