Summary
Image: ghcr.io/github/gh-aw-firewall/agent:0.27.44
- Vulnerabilities: 0 Critical / 4 High / 285 Medium / 64 Low / 19 Negligible
- License policy violations: 211
Vulnerabilities
High
GHSA-rgw5-rvv9-x895: brace-expansion@5.0.7 (fix: 5.0.9)
GHSA-mh99-v99m-4gvg: brace-expansion@5.0.7 (fix: 5.0.8)
GHSA-mwp4-54f8-5fhr: ip-address@10.2.0 (fix: 10.3.1)
CVE-2026-58043: node@22.23.1 (no fix version listed by Grype yet)
Medium (285), Low (64), Negligible (19) — full list
Predominantly base-layer (Ubuntu 22.04) packages: bind9-libs@1:9.18.39-0ubuntu0.22.04.4 (16 CVEs, e.g. CVE-2023-50387, CVE-2023-50868, CVE-2024-12705, CVE-2024-11187, CVE-2025-8677, CVE-2024-0760, CVE-2023-2828, CVE-2024-1975, CVE-2024-1737, CVE-2026-5946, CVE-2022-2795, CVE-2026-1519, CVE-2023-4408, CVE-2026-3039, CVE-2026-3104, CVE-2026-3119, CVE-2025-40778, CVE-2026-5950), libpython3.10*/python3.10*@3.10.12-1~22.04.16 (CVE-2026-7210, CVE-2026-11940, CVE-2026-15308, CVE-2020-10735), perl*@5.34.0-3ubuntu1.7 (CVE-2023-31486), libcurl*/curl@7.81.0-1ubuntu1.25 (CVE-2026-11856), php8.1-*@8.1.2-1ubuntu2.25 (CVE-2017-7189), libcairo2@1.16.0-5ubuntu2.1 (CVE-2017-7475, CVE-2018-18064), libtiff5@4.3.0-6ubuntu0.13 (CVE-2026-4775), git/git-man@1:2.34.1-1ubuntu1.17 (CVE-2018-1000021), libncurses6/libncursesw6/libtinfo6/ncurses-base/ncurses-bin@6.3-2ubuntu0.2 (CVE-2023-50495), libexpat1@2.4.7-1ubuntu0.7 (CVE-2025-59375), libzstd1@1.4.8+dfsg-3build1 (CVE-2022-4899), libjpeg-turbo8@2.1.2-0ubuntu1 (CVE-2018-10126), libpcre2-8-0@10.39-3ubuntu0.1 (CVE-2022-41409), libgcrypt20@1.9.4-3ubuntu3.2 (CVE-2024-2236), libpixman-1-0@0.40.0-1ubuntu0.22.04.1 (CVE-2023-37769), and many more inherited from the Ubuntu 22.04 base image. Full raw scan output available in the workflow run artifacts.
License Policy Violations
211 violations, dominated by standard OS base-layer GPL/LGPL-family packages (e.g. GPL-2.0-only, GPL-2.0-or-later: 12 packages; combined GPL-3.0/LGPL bundles: 11 packages) plus 14 packages with no licenses found, including:
Packages with no licenses found (14)
libcrypt1@1:4.4.27-1
logsave@1.46.5-2ubuntu1.2
libgmp10@2:6.2.1+dfsg-3ubuntu1
e2fsprogs@1.46.5-2ubuntu1.2
libnfnetlink0@1.0.1-3build3
libpam-modules-bin@1.4.0-11ubuntu2.7
libpam0g@1.4.0-11ubuntu2.7
node@22.23.1
netbase@6.3
libpam-modules@1.4.0-11ubuntu2.7
libpam-runtime@1.4.0-11ubuntu2.7
debianutils@5.5-1ubuntu2
libext2fs2@1.46.5-2ubuntu1.2
usrmerge@25ubuntu2
Remediation
- Rebuild the image against a newer Ubuntu 22.04 base layer / apply
apt-get upgrade for bind9-libs, python3.10*, perl*, curl/libcurl*, php8.1-* to pick up the referenced Medium/Low fixes where available upstream.
- Bump
node beyond 22.23.1 and upgrade brace-expansion and ip-address npm dependencies to the fixed versions (5.0.9/5.0.8 and 10.3.1 respectively) to close the 4 High-severity findings.
- Track
CVE-2026-58043 in node@22.23.1 — no fixed version currently published by Grype's feed; monitor Node.js security releases.
- Review the license-policy allowlist for standard GPL/LGPL Ubuntu base packages (bind, perl, e2fsprogs, pam, etc.) — most are expected OS components; treat as policy-tuning rather than remediation.
- Investigate the 14 "no licenses found" packages individually; most are Debian/Ubuntu native packages whose license metadata Grant cannot detect (e.g.
libpam*, e2fsprogs), but node@22.23.1 should have its license explicitly recorded/allowlisted.
Generated by 🛡️ Daily Container Image Security Scan · auto · 229 AIC · ⌖ 2.79 AIC · ⊞ 6.4K · ◷
Summary
Image:
ghcr.io/github/gh-aw-firewall/agent:0.27.44Vulnerabilities
High
GHSA-rgw5-rvv9-x895:brace-expansion@5.0.7(fix: 5.0.9)GHSA-mh99-v99m-4gvg:brace-expansion@5.0.7(fix: 5.0.8)GHSA-mwp4-54f8-5fhr:ip-address@10.2.0(fix: 10.3.1)CVE-2026-58043:node@22.23.1(no fix version listed by Grype yet)Medium (285), Low (64), Negligible (19) — full list
Predominantly base-layer (Ubuntu 22.04) packages:
bind9-libs@1:9.18.39-0ubuntu0.22.04.4(16 CVEs, e.g. CVE-2023-50387, CVE-2023-50868, CVE-2024-12705, CVE-2024-11187, CVE-2025-8677, CVE-2024-0760, CVE-2023-2828, CVE-2024-1975, CVE-2024-1737, CVE-2026-5946, CVE-2022-2795, CVE-2026-1519, CVE-2023-4408, CVE-2026-3039, CVE-2026-3104, CVE-2026-3119, CVE-2025-40778, CVE-2026-5950),libpython3.10*/python3.10*@3.10.12-1~22.04.16(CVE-2026-7210, CVE-2026-11940, CVE-2026-15308, CVE-2020-10735),perl*@5.34.0-3ubuntu1.7(CVE-2023-31486),libcurl*/curl@7.81.0-1ubuntu1.25(CVE-2026-11856),php8.1-*@8.1.2-1ubuntu2.25(CVE-2017-7189),libcairo2@1.16.0-5ubuntu2.1(CVE-2017-7475, CVE-2018-18064),libtiff5@4.3.0-6ubuntu0.13(CVE-2026-4775),git/git-man@1:2.34.1-1ubuntu1.17(CVE-2018-1000021),libncurses6/libncursesw6/libtinfo6/ncurses-base/ncurses-bin@6.3-2ubuntu0.2(CVE-2023-50495),libexpat1@2.4.7-1ubuntu0.7(CVE-2025-59375),libzstd1@1.4.8+dfsg-3build1(CVE-2022-4899),libjpeg-turbo8@2.1.2-0ubuntu1(CVE-2018-10126),libpcre2-8-0@10.39-3ubuntu0.1(CVE-2022-41409),libgcrypt20@1.9.4-3ubuntu3.2(CVE-2024-2236),libpixman-1-0@0.40.0-1ubuntu0.22.04.1(CVE-2023-37769), and many more inherited from the Ubuntu 22.04 base image. Full raw scan output available in the workflow run artifacts.License Policy Violations
211 violations, dominated by standard OS base-layer GPL/LGPL-family packages (e.g.
GPL-2.0-only, GPL-2.0-or-later: 12 packages; combinedGPL-3.0/LGPLbundles: 11 packages) plus 14 packages with no licenses found, including:Packages with no licenses found (14)
libcrypt1@1:4.4.27-1logsave@1.46.5-2ubuntu1.2libgmp10@2:6.2.1+dfsg-3ubuntu1e2fsprogs@1.46.5-2ubuntu1.2libnfnetlink0@1.0.1-3build3libpam-modules-bin@1.4.0-11ubuntu2.7libpam0g@1.4.0-11ubuntu2.7node@22.23.1netbase@6.3libpam-modules@1.4.0-11ubuntu2.7libpam-runtime@1.4.0-11ubuntu2.7debianutils@5.5-1ubuntu2libext2fs2@1.46.5-2ubuntu1.2usrmerge@25ubuntu2Remediation
apt-get upgradeforbind9-libs,python3.10*,perl*,curl/libcurl*,php8.1-*to pick up the referenced Medium/Low fixes where available upstream.nodebeyond 22.23.1 and upgradebrace-expansionandip-addressnpm dependencies to the fixed versions (5.0.9/5.0.8 and 10.3.1 respectively) to close the 4 High-severity findings.CVE-2026-58043innode@22.23.1— no fixed version currently published by Grype's feed; monitor Node.js security releases.libpam*,e2fsprogs), butnode@22.23.1should have its license explicitly recorded/allowlisted.