Skip to content

[container-image-scan] Container findings for gh-aw-firewall/api-proxy:0.27.43 #49291

Description

@github-actions

Summary

Image: ghcr.io/github/gh-aw-firewall/api-proxy:0.27.43
Pinned reference: ghcr.io/github/gh-aw-firewall/api-proxy:0.27.43@sha256:d85f57975af5ea23af4996e41ed73fbc8f5b4a47402472bfe82e508f352cb0c1

Grype found 6 vulnerabilities (1 High, 5 Medium). Grant found 35 license policy violations, predominantly GPL/LGPL Alpine base packages and BlueOak-1.0.0 npm packages.

Vulnerabilities

Vulnerability details (6 findings)

License policy violations

License violations (35 packages)
  • ca-certificates-bundle@20260611-r0 — MPL-2.0
  • glob@13.0.6 — BlueOak-1.0.0
  • spdx-license-ids@3.0.23 — CC0-1.0
  • zstd-libs@1.5.7-r2 — GPL-2.0-or-later
  • alpine-baselayout-data@3.7.2-r1 — GPL-2.0-only
  • node@22.23.1 — no licenses found
  • tar@7.5.19 — BlueOak-1.0.0
  • minipass-flush@1.0.6 — BlueOak-1.0.0
  • common-ancestor-path@2.0.0 — BlueOak-1.0.0
  • libcurl@8.21.0-r0 — curl
  • musl-utils@1.2.6-r2 — GPL-2.0-or-later
  • libstdc++@15.2.0-r5 — GPL-2.0-or-later, LGPL-2.1-or-later
  • curl@8.21.0-r0 — curl
  • libapk@3.0.6-r0 — GPL-2.0-only
  • qrcode-terminal@0.12.0 — Apache 2.0
  • scanelf@1.3.9-r1 — GPL-2.0-only
  • isexe@4.0.0 — BlueOak-1.0.0
  • libidn2@2.3.8-r0 — GPL-2.0-or-later, LGPL-3.0-or-later
  • ssl_client@1.37.0-r31 — GPL-2.0-only
  • yallist@5.0.0 — BlueOak-1.0.0
  • chownr@3.0.0 — BlueOak-1.0.0
  • npm@11.18.0 — Artistic-2.0
  • busybox@1.37.0-r31 — GPL-2.0-only
  • minipass@7.1.3 — BlueOak-1.0.0
  • minimatch@10.2.5 — BlueOak-1.0.0
  • apk-tools@3.0.6-r0 — GPL-2.0-only
  • lru-cache@11.5.1 — BlueOak-1.0.0
  • busybox-binsh@1.37.0-r31 — GPL-2.0-only
  • spdx-exceptions@2.5.0 — CC-BY-3.0
  • zlib@1.3.2-r0 — Zlib
  • awf-api-proxy@1.0.0 — no licenses found
  • path-scurry@2.0.2 — BlueOak-1.0.0
  • alpine-baselayout@3.7.2-r1 — GPL-2.0-only
  • libunistring@1.4.2-r0 — GPL-2.0-or-later, LGPL-3.0-or-later
  • libgcc@15.2.0-r5 — GPL-2.0-or-later, LGPL-2.1-or-later

Remediation

  • Bump @opentelemetry/core to ≥2.8.0, brace-expansion to ≥5.0.8, tar to ≥7.5.21 in the Node dependency tree.
  • Rebuild the base image on a newer Alpine release to pick up patched nghttp2-libs, busybox, ssl_client for CVE-2025-60876/CVE-2026-58055.
  • node@22.23.1 and awf-api-proxy@1.0.0 (the in-repo package) report "no licenses found" — attach an explicit license declaration/SPDX identifier to awf-api-proxy and verify Node's SBOM metadata.
  • GPL/LGPL findings are standard Alpine base packages; confirm license policy exemption for OS base layers or add an explicit allow-list.

Generated by 🛡️ Daily Container Image Security Scan · auto · 370.7 AIC · ⌖ 9.22 AIC · ⊞ 6.3K ·

Metadata

Metadata

Assignees

No one assigned

    Labels

    cookieIssue Monster Loves Cookies!security

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions