Skip to content

[WIP] Fix vulnerabilities detected in container image a3d33153b6ab#47833

Closed
pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/container-image-scan-fix-vulnerabilities
Closed

[WIP] Fix vulnerabilities detected in container image a3d33153b6ab#47833
pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/container-image-scan-fix-vulnerabilities

Conversation

Copilot AI commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Thanks for asking me to work on this. I will get started on it and keep this PR's description up to date as I form a plan and make progress.


This section details on the original issue you should resolve

<issue_title>[container-image-scan] Container findings for a3d33153b6ab</issue_title>
<issue_description>## Container Scan Findings

Scan date: 2026-07-24
Tools: Syft 1.49.0 · Grype 0.116.0 · Grant 0.6.8
Grype DB: v6.1.9, built 2026-07-23T07:03:49Z, status: valid


Image

Field Value
Tag ghcr.io/github/gh-aw-firewall/api-proxy:0.27.41
Pinned digest sha256:a3d33153b6abb2dd39540ef7def8aa8a5020022c11822d88f5b87ebe350276d1
Current digest sha256:6e2200dcb6a62b183cdcf7ed86e44713ba5ed8eeaf8de143319458898b6e8118
Platform linux/amd64 → sha256:a3d33153b6abb2dd39540ef7def8aa8a5020022c11822d88f5b87ebe350276d1

⚠️ Digest drift detected.


Vulnerabilities (5 total · 0 critical · 1 fixable)

Platform: linux/amd64

Severity ID Package Installed Fixed In Type
Medium CVE-2025-60876 busybox 1.37.0-r31 apk
Medium CVE-2025-60876 busybox-binsh 1.37.0-r31 apk
Medium CVE-2025-60876 ssl_client 1.37.0-r31 apk
Medium GHSA-8988-4f7v-96qf @opentelemetry/core 1.30.1 2.8.0 npm
Medium CVE-2026-58055 nghttp2-libs 1.69.0-r0 apk

License Findings (Grant)

Policy allows: MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISC
Status: noncompliant — 193 packages; 34 denied, 2 unlicensed

License Packages Risk
GPL-2.0-only 8 High
GPL-2.0-or-later 6 High
BlueOak-1.0.0 11 Unknown
LGPL-2.1-or-later 2 Medium
LGPL-3.0-or-later 2 Medium
MPL-2.0 1 Medium
curl 2 Unknown
CC-BY-3.0 1 Unknown
CC0-1.0 1 Unknown
Artistic-2.0 1 Low (non-allowed)
(no licenses found) 2 Unknown

Remediation

  1. Upgrade @opentelemetry/core to ≥2.8.0 (GHSA-8988-4f7v-96qf, fixable now).
  2. Update Alpine base for busybox CVE-2025-60876 when a fix is available.
  3. Re-pin image to sha256:6e2200dcb6a62b183cdcf7ed86e44713ba5ed8eeaf8de143319458898b6e8118 after validation.
  4. Audit 34 denied packages; remove unnecessary GPL/LGPL components or obtain legal approval.

Generated by 🛡️ Daily Container Image Security Scan · sonnet46 · 65.9 AIC · ⌖ 7.3 AIC · ⊞ 4.5K ·

Comments on the Issue (you are @copilot in this section)

Copilot AI linked an issue Jul 24, 2026 that may be closed by this pull request
@pelikhan pelikhan closed this Jul 24, 2026
Copilot stopped work on behalf of pelikhan due to an error July 24, 2026 17:47
Copilot AI requested a review from pelikhan July 24, 2026 17:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[container-image-scan] Container findings for a3d33153b6ab

2 participants