Skip to content

[WIP] Fix container scan findings for image tag 0.27.37#47481

Closed
pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/container-image-scan-findings-0d35e8682845
Closed

[WIP] Fix container scan findings for image tag 0.27.37#47481
pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/container-image-scan-findings-0d35e8682845

Conversation

Copilot AI commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Thanks for asking me to work on this. I will get started on it and keep this PR's description up to date as I form a plan and make progress.


This section details on the original issue you should resolve

<issue_title>[container-image-scan] Container findings for 0d35e8682845</issue_title>
<issue_description>## Container Scan Report

Scan date: 2026-07-23
Scanner versions: Syft 1.49.0 · Grype 0.116.0 · Grant 0.6.8
Grype DB: Schema v6.1.9, built 2026-07-22T07:06:24Z — status: valid


Image

Field Value
Image tag ghcr.io/github/gh-aw-firewall/agent:0.27.37
Pinned image ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67
Index digest sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67
Digest drift No

Platform digests

Platform Digest
linux/amd64 sha256:245d228c4d339eb78694682c28479e9e32bf29fcc7747c8b4e00b757fbe9851b
linux/arm64 sha256:81f01ad52af241e6f663f037a26f8e9233c82e9bd74dae5673755097d4e26307

Vulnerability Summary

Total: 1296 · Critical: 22 · Fixable: 456

Vulnerabilities are identical across amd64 and arm64 (same packages). Table lists amd64 scan findings.

Vulnerabilities (648 entries — click to expand)
Package Installed Fixed In Type Vulnerability Severity
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2023-44487 High
stdlib go1.18 1.21.9, 1.22.2 go-module GO-2024-2687 High
stdlib go1.18.1 1.21.9, 1.22.2 go-module GO-2024-2687 High
stdlib go1.18 1.19.8, 1.20.3 go-module GO-2023-1703 Critical
stdlib go1.18.1 1.19.8, 1.20.3 go-module GO-2023-1703 Critical
stdlib go1.18 1.21.11, 1.22.4 go-module GO-2024-2887 Critical
stdlib go1.18.1 1.21.11, 1.22.4 go-module GO-2024-2887 Critical
stdlib go1.18 1.19.9, 1.20.4 go-module GO-2023-1752 Critical
stdlib go1.18.1 1.19.9, 1.20.4 go-module GO-2023-1752 Critical
stdlib go1.18 1.24.13, 1.25.7 go-module GO-2026-4337 Critical
stdlib go1.18.1 1.24.13, 1.25.7 go-module GO-2026-4337 Critical
stdlib go1.18 1.23.8, 1.24.2 go-module GO-2025-3563 Critical
stdlib go1.18.1 1.23.8, 1.24.2 go-module GO-2025-3563 Critical
tar 7.5.11 7.5.19 npm GHSA-23hp-3jrh-7fpw Critical
bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb CVE-2023-50387 Medium
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2024-27983 Medium
bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb CVE-2023-50868 Medium
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2024-6119 Medium
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2025-15467 Medium
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2026-21710 Medium
bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb CVE-2024-12705 Medium
bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb CVE-2024-11187 Medium
stdlib go1.18 1.17.9, 1.18.1 go-module GO-2022-0433 High
bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb CVE-2025-8677 Medium
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2021-44532 Medium
stdlib go1.18 1.19.6, 1.20.1 go-module GO-2023-1571 High
stdlib go1.18.1 1.19.6, 1.20.1 go-module GO-2023-1571 High
stdlib go1.18 1.17.9, 1.18.1 go-module GO-2022-0435 High
stdlib go1.18 1.18.9, 1.19.4 go-module GO-2022-1144 Medium
stdlib go1.18.1 1.18.9, 1.19.4 go-module GO-2022-1144 Medium
stdlib go1.18 1.20.10, 1.21.3 go-module GO-2023-2102 High
stdlib go1.18.1 1.20.10, 1.21.3 go-module GO-2023-2102 High
bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb CVE-2024-0760 Medium
stdlib go1.18 1.20.11, 1.21.4 go-module GO-2023-2185 High
stdlib go1.18.1 1.20.11, 1.21.4 go-module GO-2023-2185 High
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2026-45447 High
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2023-3446 Low
stdlib go1.18 1.18.6, 1.19.1 go-module GO-2022-0969 High
stdlib go1.18.1 1.18.6, 1.19.1 go-module GO-2022-0969 High
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2025-59465 Medium
bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb CVE-2023-2828 Medium
stdlib go1.18 1.21.11, 1.22.4 go-module GO-2024-2887 Critical
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2024-9143 Low
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2025-55131 Medium
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2024-5535 Low
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2023-5363 Medium
stdlib go1.18 1.17.11, 1.18.3 go-module GO-2022-0477 High
stdlib go1.18.1 1.17.11, 1.18.3 go-module GO-2022-0477 High
stdlib go1.18 1.17.13, 1.18.5 go-module GO-2022-0537 High
stdlib go1.18.1 1.17.13, 1.18.5 go-module GO-2022-0537 High
stdlib go1.18 1.24.12, 1.25.6 go-module GO-2026-4341 High
stdlib go1.18.1 1.24.12, 1.25.6 go-module GO-2026-4341 High
stdlib go1.18 1.19.8, 1.20.3 go-module GO-2023-1704 High
stdlib go1.18.1 1.19.8, 1.20.3 go-module GO-2023-1704 High
stdlib go1.18 1.17.12, 1.18.4 go-module GO-2022-0521 High
stdlib go1.18.1 1.17.12, 1.18.4 go-module GO-2022-0521 High
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2026-48933 Medium
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2023-5678 Low
stdlib go1.18 1.17.10, 1.18.2 go-module GO-2022-0493 Medium
stdlib go1.18.1 1.17.10, 1.18.2 go-module GO-2022-0493 Medium
stdlib go1.18 1.17.11, 1.18.3 go-module GO-2022-0533 High
stdlib go1.18.1 1.17.11, 1.18.3 go-module GO-2022-0533 High
stdlib go1.18 1.19.6, 1.20.1 go-module GO-2023-1568 High
stdlib go1.18.1 1.19.6, 1.20.1 go-module GO-2023-1568 High
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2026-48618 Medium
stdlib go1.18 1.17.12, 1.18.4 go-module GO-2022-0527 High
stdlib go1.18.1 1.17.12, 1.18.4 go-module GO-2022-0527 High
stdlib go1.18 1.17.12, 1.18.4 go-module GO-2022-0522 High
stdlib go1.18 1.17.12, 1.18.4 go-module GO-2022-0523 High
stdlib go1.18.1 1.17.12, 1.18.4 go-module GO-2022-0522 High
stdlib go1.18.1 1.17.12, 1.18.4 go-module GO-2022-0523 High
stdlib go1.18 1.17.12, 1.18.4 go-module GO-2022-0524 High
stdlib go1.18.1 1.17.12, 1.18.4 go-module GO-2022-0524 High
stdlib go1.18 1.18.7, 1.19.2 go-module GO-2022-1037 High
stdlib go1.18.1 1.18.7, 1.19.2 go-module GO-2022-1037 High
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2019-1563 Low
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2022-40735 Medium
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2025-9231 Medium
stdlib go1.18 1.19.8, 1.20.3 go-module GO-2023-1705 High
stdlib go1.18.1 1.19.8, 1.20.3 go-module GO-2023-1705 High
nodejs 22.23.1-1nodesource1 (won't fix) deb CVE-2023-0464 Low
stdlib go1.18 1.18.1 go-module GO-2022-0434 High
(and ~560 more entries — see full grype-image-01-linux-amd64.json for complete list)

Rejected Licenses (Grant)

Policy: Allow MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISC only.

Platform Packages cataloged Denied Denied licenses
linux/amd64 418 (407 evaluated) 220 GPL-2.0-only (51), GPL-2.0-or-later (44), LGPL-2.1-only (41), LGPL-2.1-or-later (29), GPL-3.0-or-later (29), GPL-3.0-only (28), LGPL-3.0-or-later (23), CC0-1.0 (19), non-SPDX hashes (95)
linux/arm64 418 (407 evaluated) 220 Same as amd64

Examples of denied packages: python3-minimal (non-SPDX), psmisc (GPL-2.0), libhogweed6 (GPL/LGPL composite), dpkg (GPL-2.0-or-later), libxau6 (non-SPDX hash), and 215 others.


Remediation

  • Go stdlib: Upgrade from go1.18 / go1.18.1 to ≥ go1.25.7 (or 1.26.4) to fix all Go-module CVEs including 22 critical entries.
  • nodejs: nodejs 22.23.1-1nodesource1 has no upstream fix for several CVEs (won't-fix); evaluate pinning a newer NodeSource release or switching base image.
  • bind9-libs: Upgrade to address CVE-2023-50387, CVE-2023-50868, and related DNS-related DoS issues.
  • tar (npm): Upgrade to ≥ 7.5.19 to fix critical GHSA-23hp-3jrh-7fpw.
  • License policy: 220 packages denied under the current allow-list (only MIT/Apache-2.0/BSD/ISC). Review whether GPL/LGPL/CC0 use is intentional and update policy or replace packages accordingly.
  • Rebuild the image with an updated Go toolchain and refreshed base packages.

Generated by 🛡️ Daily Container Image Security Scan · sonnet46 122.8 AIC · ⌖ 10 AIC · ⊞ 4.5K ·

Comments on the Issue (you are @copilot in this section)

Copilot AI linked an issue Jul 23, 2026 that may be closed by this pull request
@pelikhan pelikhan closed this Jul 23, 2026
Copilot stopped work on behalf of pelikhan due to an error July 23, 2026 06:13
Copilot AI requested a review from pelikhan July 23, 2026 06:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[container-image-scan] Container findings for 0d35e8682845

2 participants