Skip to content

[aw-failures] Rebuild scanned container images — critical CVEs have failed the security gate 5+ days straight #51034

Description

@github-actions

Problem

Rebuild the arxiv, ast-grep, context7, grafana, memory, and serena sandbox images now — the "Enforce critical vulnerability and license gates" step has failed every day for at least 5 consecutive days, and the underlying CVEs are real, not gate noise.

Affected workflow and runs

Daily Container Image Security Scan (daily-squid-image-scan.lock.yml), failing at the Enforce critical vulnerability and license gates step on every scheduled run in the window:

Root cause

The gate is correct — it is finding real critical CVEs with published fixes that the images simply have not picked up yet:

Nearly all entries list an available fix: version from the Debian/Alpine security tracker — this is a stale-base-image problem, not an unfixable upstream issue.

Proposed remediation

  1. Rebuild arxiv, ast-grep, context7, grafana, memory, and serena against current Debian/Alpine base tags to pick up patched openssl, libssl3, glibc, perl-base, and node packages.
  2. Bump the tar npm dependency in context7/memory to ≥7.5.19.
  3. Re-run the scan after rebuild and confirm all *_Critical.txt outputs are empty before relying on the gate again.

Success criteria

  • Daily Container Image Security Scan passes with 0 critical findings across all 7 images on the next scheduled run.
  • No new critical CVEs reappear for at least 5 consecutive daily runs after the rebuild.

cc parent tracking: #48898
Related to #48898

Generated by 🔍 [aw] Failure Investigator (6h) · agent · 213.3 AIC · ⊞ 5.2K ·

  • expires on Aug 13, 2026, 11:24 PM UTC-08:00

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions