Skip to content

[WIP] Fix container image scan findings for 0d35e8682845#47518

Closed
pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/container-image-scan-0d35e8682845
Closed

[WIP] Fix container image scan findings for 0d35e8682845#47518
pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/container-image-scan-0d35e8682845

Conversation

Copilot AI commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Thanks for asking me to work on this. I will get started on it and keep this PR's description up to date as I form a plan and make progress.


This section details on the original issue you should resolve

<issue_title>[container-image-scan] Container findings for 0d35e8682845</issue_title>
<issue_description>## Container Scan Findings

Scan date: 2026-07-23 | Tools: Syft 1.49.0 · Grype 0.116.0 · Grant 0.6.8
Grype DB: built 2026-07-22T07:06:24Z, schema v6.1.9, status valid


Image

Field Value
Tag ghcr.io/github/gh-aw-firewall/agent:0.27.37
Pinned digest sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67
Current digest sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67
Digest drift None

Platform digests

Platform Digest
linux/amd64 sha256:245d228c4d339eb78694682c28479e9e32bf29fcc7747c8b4e00b757fbe9851b
linux/arm64 sha256:81f01ad52af241e6f663f037a26f8e9233c82e9bd74dae5673755097d4e26307

Vulnerability Summary

Total Critical Fixable
1296 22 456

Vulnerabilities (linux/amd64 — notable Critical and High)

Severity ID Package Installed Fixed In
Critical GO-2023-1703 stdlib go1.18, go1.18.1 *1.19.8, 1.20.3
Critical GO-2023-1752 stdlib go1.18, go1.18.1 *1.19.9, 1.20.4
Critical GO-2024-2887 stdlib go1.18, go1.18.1 *1.21.11, 1.22.4
Critical GO-2025-3563 stdlib go1.18, go1.18.1 *1.23.8, 1.24.2
Critical GO-2026-4337 stdlib go1.18, go1.18.1 *1.24.13, 1.25.7, 1.26.0-rc.3
Critical GHSA-23hp-3jrh-7fpw tar 7.5.11 7.5.19
High (KEV) CVE-2023-44487 nodejs 22.23.1-1nodesource1 won't fix
High GO-2024-2687 stdlib go1.18, go1.18.1 *1.21.9, 1.22.2
High CVE-2026-45447 nodejs 22.23.1-1nodesource1 won't fix
High GO-2022-0433 stdlib go1.18 1.17.9, *1.18.1
High GO-2023-1571 stdlib go1.18, go1.18.1 *1.19.6, 1.20.1
High GO-2023-2102 stdlib go1.18, go1.18.1 *1.20.10, 1.21.3
High GO-2023-2185 stdlib go1.18, go1.18.1 *1.20.11, 1.21.4
High GO-2026-4341 stdlib go1.18, go1.18.1 *1.24.12, 1.25.6
Medium CVE-2023-50387 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 none
Medium CVE-2024-27983 nodejs 22.23.1-1nodesource1 won't fix
Medium CVE-2023-50868 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 none

Note: 1296 total vulnerabilities across both platforms (arm64 matches amd64). Only representative entries shown above; see grype-image-01-linux-amd64.txt and grype-image-01-linux-arm64.txt for full list.


License Compliance (Grant)

Policy: allow MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISC; require known license.

Platform Catalogued Allowed Denied Non-SPDX
linux/amd64 418 187 220 95
linux/arm64 similar 220

Rejected license categories (amd64): GPL-1.0-only, GPL-1.0-or-later, GPL-2.0-only, GPL-2.0-or-later, GPL-3.0-only, GPL-3.0-or-later, LGPL-2.0-only, LGPL-2.1-only, AGPL variants, CC-BY-3.0, CC-BY-4.0, CC-BY-SA-3.0, CC0-1.0, MPL-2.0, Artistic, Artistic-2.0, BlueOak-1.0.0, Zlib, curl, and numerous LicenseRef-* non-SPDX identifiers.

2 packages have no license declared.


Operational Errors

None.


Remediation

  • stdlib (go1.18/1.18.1): Rebuild image with Go ≥ 1.26.4. Multiple Critical CVEs are addressed in later releases.
  • nodejs (22.23.1-1nodesource1): Several High/Medium CVEs marked "won't fix" by upstream — evaluate whether the nodejs deb package can be replaced or pinned to a version with fixes.
  • tar (7.5.11 npm): Upgrade to ≥ 7.5.19 to fix GHSA-23hp-3jrh-7fpw (Critical).
  • bind9-libs: No upstream fix available yet; monitor for security updates.
  • License rejections: 220 packages include GPL, LGPL, CC, MPL, and other non-allowed licenses. Conduct a license review and replace or exempt packages as per policy.

Generated by 🛡️ Daily Container Image Security Scan · sonnet46 78.7 AIC · ⌖ 8.9 AIC · ⊞ 4.5K ·

Comments on the Issue (you are @copilot in this section)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[container-image-scan] Container findings for 0d35e8682845

2 participants