Summary
Image: ghcr.io/github/gh-aw-firewall/api-proxy:0.27.43
Pinned reference: ghcr.io/github/gh-aw-firewall/api-proxy:0.27.43@sha256:d85f57975af5ea23af4996e41ed73fbc8f5b4a47402472bfe82e508f352cb0c1
Grype found 6 vulnerabilities (1 High, 5 Medium). Grant found 35 license policy violations, predominantly GPL/LGPL Alpine base packages and BlueOak-1.0.0 npm packages.
Vulnerabilities
Vulnerability details (6 findings)
License policy violations
License violations (35 packages)
ca-certificates-bundle@20260611-r0 — MPL-2.0
glob@13.0.6 — BlueOak-1.0.0
spdx-license-ids@3.0.23 — CC0-1.0
zstd-libs@1.5.7-r2 — GPL-2.0-or-later
alpine-baselayout-data@3.7.2-r1 — GPL-2.0-only
node@22.23.1 — no licenses found
tar@7.5.19 — BlueOak-1.0.0
minipass-flush@1.0.6 — BlueOak-1.0.0
common-ancestor-path@2.0.0 — BlueOak-1.0.0
libcurl@8.21.0-r0 — curl
musl-utils@1.2.6-r2 — GPL-2.0-or-later
libstdc++@15.2.0-r5 — GPL-2.0-or-later, LGPL-2.1-or-later
curl@8.21.0-r0 — curl
libapk@3.0.6-r0 — GPL-2.0-only
qrcode-terminal@0.12.0 — Apache 2.0
scanelf@1.3.9-r1 — GPL-2.0-only
isexe@4.0.0 — BlueOak-1.0.0
libidn2@2.3.8-r0 — GPL-2.0-or-later, LGPL-3.0-or-later
ssl_client@1.37.0-r31 — GPL-2.0-only
yallist@5.0.0 — BlueOak-1.0.0
chownr@3.0.0 — BlueOak-1.0.0
npm@11.18.0 — Artistic-2.0
busybox@1.37.0-r31 — GPL-2.0-only
minipass@7.1.3 — BlueOak-1.0.0
minimatch@10.2.5 — BlueOak-1.0.0
apk-tools@3.0.6-r0 — GPL-2.0-only
lru-cache@11.5.1 — BlueOak-1.0.0
busybox-binsh@1.37.0-r31 — GPL-2.0-only
spdx-exceptions@2.5.0 — CC-BY-3.0
zlib@1.3.2-r0 — Zlib
awf-api-proxy@1.0.0 — no licenses found
path-scurry@2.0.2 — BlueOak-1.0.0
alpine-baselayout@3.7.2-r1 — GPL-2.0-only
libunistring@1.4.2-r0 — GPL-2.0-or-later, LGPL-3.0-or-later
libgcc@15.2.0-r5 — GPL-2.0-or-later, LGPL-2.1-or-later
Remediation
- Bump
@opentelemetry/core to ≥2.8.0, brace-expansion to ≥5.0.8, tar to ≥7.5.21 in the Node dependency tree.
- Rebuild the base image on a newer Alpine release to pick up patched
nghttp2-libs, busybox, ssl_client for CVE-2025-60876/CVE-2026-58055.
node@22.23.1 and awf-api-proxy@1.0.0 (the in-repo package) report "no licenses found" — attach an explicit license declaration/SPDX identifier to awf-api-proxy and verify Node's SBOM metadata.
- GPL/LGPL findings are standard Alpine base packages; confirm license policy exemption for OS base layers or add an explicit allow-list.
Generated by 🛡️ Daily Container Image Security Scan · auto · 370.7 AIC · ⌖ 9.22 AIC · ⊞ 6.3K · ◷
Summary
Image:
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.43Pinned reference:
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.43@sha256:d85f57975af5ea23af4996e41ed73fbc8f5b4a47402472bfe82e508f352cb0c1Grype found 6 vulnerabilities (1 High, 5 Medium). Grant found 35 license policy violations, predominantly GPL/LGPL Alpine base packages and BlueOak-1.0.0 npm packages.
Vulnerabilities
Vulnerability details (6 findings)
brace-expansion@5.0.7(fix: 5.0.8)@opentelemetry/core@1.30.1(fix: 2.8.0)busybox@1.37.0-r31busybox-binsh@1.37.0-r31ssl_client@1.37.0-r31nghttp2-libs@1.69.0-r0tar@7.5.19(fix: 7.5.21)License policy violations
License violations (35 packages)
ca-certificates-bundle@20260611-r0— MPL-2.0glob@13.0.6— BlueOak-1.0.0spdx-license-ids@3.0.23— CC0-1.0zstd-libs@1.5.7-r2— GPL-2.0-or-lateralpine-baselayout-data@3.7.2-r1— GPL-2.0-onlynode@22.23.1— no licenses foundtar@7.5.19— BlueOak-1.0.0minipass-flush@1.0.6— BlueOak-1.0.0common-ancestor-path@2.0.0— BlueOak-1.0.0libcurl@8.21.0-r0— curlmusl-utils@1.2.6-r2— GPL-2.0-or-laterlibstdc++@15.2.0-r5— GPL-2.0-or-later, LGPL-2.1-or-latercurl@8.21.0-r0— curllibapk@3.0.6-r0— GPL-2.0-onlyqrcode-terminal@0.12.0— Apache 2.0scanelf@1.3.9-r1— GPL-2.0-onlyisexe@4.0.0— BlueOak-1.0.0libidn2@2.3.8-r0— GPL-2.0-or-later, LGPL-3.0-or-laterssl_client@1.37.0-r31— GPL-2.0-onlyyallist@5.0.0— BlueOak-1.0.0chownr@3.0.0— BlueOak-1.0.0npm@11.18.0— Artistic-2.0busybox@1.37.0-r31— GPL-2.0-onlyminipass@7.1.3— BlueOak-1.0.0minimatch@10.2.5— BlueOak-1.0.0apk-tools@3.0.6-r0— GPL-2.0-onlylru-cache@11.5.1— BlueOak-1.0.0busybox-binsh@1.37.0-r31— GPL-2.0-onlyspdx-exceptions@2.5.0— CC-BY-3.0zlib@1.3.2-r0— Zlibawf-api-proxy@1.0.0— no licenses foundpath-scurry@2.0.2— BlueOak-1.0.0alpine-baselayout@3.7.2-r1— GPL-2.0-onlylibunistring@1.4.2-r0— GPL-2.0-or-later, LGPL-3.0-or-laterlibgcc@15.2.0-r5— GPL-2.0-or-later, LGPL-2.1-or-laterRemediation
@opentelemetry/coreto ≥2.8.0,brace-expansionto ≥5.0.8,tarto ≥7.5.21 in the Node dependency tree.nghttp2-libs,busybox,ssl_clientfor CVE-2025-60876/CVE-2026-58055.node@22.23.1andawf-api-proxy@1.0.0(the in-repo package) report "no licenses found" — attach an explicit license declaration/SPDX identifier toawf-api-proxyand verify Node's SBOM metadata.