UK AI Open Code Risk & Resilience Governance — Remediation Item
Tier: C — Restricted Pending Review
SLA Urgency: Critical
Risk-Scoring Breakdown
| Dimension |
Score |
| Exposure amplification |
High (supply-chain, multiple production/build images) |
| Patchability |
Medium (upstream-dependent) |
| Detectability |
High (grype tracked, per-image issues filed) |
| Operational fragility |
Medium |
| Ownership confidence |
High (dedicated issue per image already exists) |
Finding
The [static-analysis] Report - 2026-08-12 (#52235) shows grype found 1325 total CVEs across 10 scanned container images: 67 Critical, 438 High, 776 Medium, 44 Unknown. Six images each have a dedicated open [container-image-scan] tracking issue (node:lts-alpine, ghcr.io/github/gh-aw-mcpg:v0.4.8, ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44, ghcr.io/github/github-mcp-server:v1.8.0, ghcr.io/github/gh-aw-firewall/squid:0.27.44, ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.44, ghcr.io/github/gh-aw-firewall/agent:0.27.44), but the aggregate Critical/High volume is large relative to observed remediation velocity.
Positively, this week showed active remediation behavior (container/dependency replacements landing same-week as findings), but the Critical/High backlog volume still warrants a consolidated, prioritized burn-down effort rather than per-image issue handling alone.
Remediation Action
- Triage the 67 Critical findings first across all 10 images; confirm exploitability/reachability given the images' runtime roles (agent execution, firewall proxy, MCP gateway).
- Establish or confirm an SLA-driven image update cadence (e.g., weekly base-image bump + rebuild) to keep pace with new CVE disclosures.
- Consolidate tracking across the six open per-image issues to avoid duplicated triage effort; link this issue as the parent tracking item.
Reference
Full governance analysis: see the linked discussion report "UK AI Open Code Risk & Resilience Governance Report — 2026-08-12 (github/gh-aw)" created in this same workflow run. Source data: issue #52235.
Generated by UK AI Operational Resilience · auto · 68.1 AIC · ⌖ 2.22 AIC · ⊞ 8.7K · ◷
UK AI Open Code Risk & Resilience Governance — Remediation Item
Tier: C — Restricted Pending Review
SLA Urgency: Critical
Risk-Scoring Breakdown
Finding
The [static-analysis] Report - 2026-08-12 (#52235) shows grype found 1325 total CVEs across 10 scanned container images: 67 Critical, 438 High, 776 Medium, 44 Unknown. Six images each have a dedicated open
[container-image-scan]tracking issue (node:lts-alpine, ghcr.io/github/gh-aw-mcpg:v0.4.8, ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44, ghcr.io/github/github-mcp-server:v1.8.0, ghcr.io/github/gh-aw-firewall/squid:0.27.44, ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.44, ghcr.io/github/gh-aw-firewall/agent:0.27.44), but the aggregate Critical/High volume is large relative to observed remediation velocity.Positively, this week showed active remediation behavior (container/dependency replacements landing same-week as findings), but the Critical/High backlog volume still warrants a consolidated, prioritized burn-down effort rather than per-image issue handling alone.
Remediation Action
Reference
Full governance analysis: see the linked discussion report "UK AI Open Code Risk & Resilience Governance Report — 2026-08-12 (github/gh-aw)" created in this same workflow run. Source data: issue #52235.