Skip to content

[container-image-scan] Container findings for 053ba306623a #47737

Description

@github-actions

Container Scan Findings

Scan date: 2026-07-24
Tools: Syft 1.49.0 · Grype 0.116.0 · Grant 0.6.8
Grype DB: v6.1.9, built 2026-07-23T07:03:49Z, status: valid


Image

Field Value
Tag ghcr.io/github/gh-aw-firewall/agent:0.27.41
Pinned digest sha256:053ba306623a1a0d4c3c5ac9a2c3dc3217ce04d44329b61929fe7f8b0dc457f3
Current digest sha256:e39efa0edf10c0d0bfc572b59a186dfccb1973f0f77e224bcf6e5a7d81ee95c8
Platform linux/amd64 → sha256:053ba306623a1a0d4c3c5ac9a2c3dc3217ce04d44329b61929fe7f8b0dc457f3

⚠️ Digest drift detected. The current tag digest differs from the pinned digest. The image has been updated since pinning.


Vulnerabilities (365 total · 1 critical · 43 fixable)

Platform: linux/amd64

Severity ID Package Installed Fixed In Type
Critical GO-2026-4337 stdlib go1.24.6 *1.24.13, 1.25.7, 1.26.0-rc.3 go-module
High GO-2026-4341 stdlib go1.24.6 *1.24.12, 1.25.6 go-module
High GO-2026-5037 stdlib go1.24.6 *1.25.11, 1.26.4 go-module
High GO-2026-4981 stdlib go1.24.6 *1.25.10, 1.26.3 go-module
High GO-2026-4977 stdlib go1.24.6 *1.25.10, 1.26.3 go-module
High GO-2026-4986 stdlib go1.24.6 *1.25.10, 1.26.3 go-module
High GO-2026-4918 stdlib go1.24.6 *1.25.10, 1.26.3 go-module
High GO-2026-4601 stdlib go1.24.6 *1.25.8, 1.26.1 go-module
High GO-2025-4009 stdlib go1.24.6 *1.24.8, 1.25.2 go-module
High GO-2026-4870 stdlib go1.24.6 *1.25.9, 1.26.2 go-module
High GO-2026-4947 stdlib go1.24.6 *1.25.9, 1.26.2 go-module
High GO-2025-4006 stdlib go1.24.6 *1.24.8, 1.25.2 go-module
High GO-2026-4971 stdlib go1.24.6 *1.25.10, 1.26.3 go-module
High GO-2026-5038 stdlib go1.24.6 *1.25.11, 1.26.4 go-module
High GO-2025-4007 stdlib go1.24.6 *1.24.9, 1.25.3 go-module
High GO-2025-4013 stdlib go1.24.6 *1.24.8, 1.25.2 go-module
High GO-2026-4946 stdlib go1.24.6 *1.25.9, 1.26.2 go-module
High GO-2025-4155 stdlib go1.24.6 *1.24.11, 1.25.5 go-module
High GO-2026-4970 stdlib (×2) go1.24.6 / go1.26.4 *1.25.12, 1.26.5, 1.27.0-rc.2 go-module
Medium CVE-2023-50387 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb
Medium CVE-2023-50868 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb
Medium CVE-2024-12705 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb
Medium CVE-2024-11187 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb
Medium CVE-2025-8677 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb
Medium CVE-2024-0760 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb
Medium CVE-2023-2828 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb
Medium CVE-2026-11856 curl / libcurl3-gnutls / libcurl4 7.81.0-1ubuntu1.25 won't fix deb
Medium CVE-2026-5946 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb
Medium CVE-2023-31486 perl / perl-base / perl-modules-5.34 / libperl5.34 5.34.0-3ubuntu1.7 won't fix deb
Medium CVE-2022-2795 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb
Medium CVE-2026-1519 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb
Medium CVE-2024-1737 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb
Medium CVE-2024-1975 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb
Medium CVE-2023-4408 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb
Medium CVE-2025-59375 libexpat1 2.4.7-1ubuntu0.7 deb
Medium CVE-2026-7210 python3.10 / libpython3.10-* 3.10.12-1~22.04.16 deb
Medium CVE-2026-11940 python3.10 / libpython3.10-* 3.10.12-1~22.04.16 deb
Medium CVE-2026-13221 perl* 5.34.0-3ubuntu1.7 deb
Medium CVE-2026-26740 libgif7 5.1.9-2ubuntu0.3 deb
Medium CVE-2026-15308 python3.10 / libpython3.10-* 3.10.12-1~22.04.16 deb
Medium CVE-2026-3039 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb
Medium CVE-2026-3104 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb
Medium CVE-2026-3119 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb
Medium CVE-2026-4775 libtiff5 4.3.0-6ubuntu0.13 deb
Medium CVE-2026-5950 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb
Medium CVE-2026-3591 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb
Medium CVE-2026-3592 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb
Medium CVE-2026-40355 libgssapi-krb5-2 / libk5crypto3 / libkrb5-3 / libkrb5support0 1.19.2-2ubuntu0.8 deb
Medium CVE-2026-40356 libgssapi-krb5-2 / libk5crypto3 / libkrb5-3 / libkrb5support0 1.19.2-2ubuntu0.8 deb
Medium CVE-2024-52005 git / git-man 1:2.34.1-1ubuntu1.17 deb
Medium CVE-2026-5450 libc-bin / libc6 2.35-0ubuntu3.13 deb
Medium CVE-2025-40778 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb
Medium CVE-2025-40780 bind9-libs 1:9.18.39-0ubuntu0.22.04.4 deb
Medium CVE-2026-59843 libssh-4 0.9.6-2ubuntu0.22.04.7 deb
Medium CVE-2026-59844 libssh-4 0.9.6-2ubuntu0.22.04.7 deb
Medium CVE-2026-9538 perl* 5.34.0-3ubuntu1.7 deb
Medium CVE-2026-11972 python3.10 / libpython3.10-* 3.10.12-1~22.04.16 deb
Medium CVE-2026-45186 libexpat1 2.4.7-1ubuntu0.7 deb
Medium CVE-2026-58016 libglib2.0-0 2.72.4-0ubuntu2.9 deb
Medium CVE-2026-58015 libglib2.0-0 2.72.4-0ubuntu2.9 deb
Medium CVE-2026-42497 perl* 5.34.0-3ubuntu1.7 deb
Medium CVE-2026-12087 perl* 5.34.0-3ubuntu1.7 deb
Medium CVE-2026-4046 libc-bin / libc6 2.35-0ubuntu3.13 deb
Medium CVE-2026-48959 perl* 5.34.0-3ubuntu1.7 deb
Medium CVE-2026-5928 libc-bin / libc6 2.35-0ubuntu3.13 deb
Medium CVE-2026-6238 libc-bin / libc6 2.35-0ubuntu3.13 deb
Medium CVE-2026-58011 libglib2.0-0 2.72.4-0ubuntu2.9 deb
Medium CVE-2026-59842 libssh-4 0.9.6-2ubuntu0.22.04.7 deb
Medium CVE-2026-54411 libpam* 1.4.0-11ubuntu2.7 deb
Medium CVE-2026-57433 perl* 5.34.0-3ubuntu1.7 deb
Medium CVE-2026-58013 libglib2.0-0 2.72.4-0ubuntu2.9 deb
Medium CVE-2026-58010 libglib2.0-0 2.72.4-0ubuntu2.9 deb
Medium CVE-2026-58012 libglib2.0-0 2.72.4-0ubuntu2.9 deb
Medium CVE-2026-48962 perl* 5.34.0-3ubuntu1.7 deb
Medium CVE-2026-58014 libglib2.0-0 2.72.4-0ubuntu2.9 deb
Medium CVE-2026-41080 libexpat1 2.4.7-1ubuntu0.7 deb
Medium CVE-2026-4739 libexpat1 2.4.7-1ubuntu0.7 deb
Medium CVE-2026-48961 perl* 5.34.0-3ubuntu1.7 deb
Medium CVE-2026-59847 libssh-4 0.9.6-2ubuntu0.22.04.7 deb
Medium CVE-2026-59848 libssh-4 0.9.6-2ubuntu0.22.04.7 deb
Medium CVE-2024-10041 libpam* 1.4.0-11ubuntu2.7 won't fix deb
Medium CVE-2026-7210 libpython3.10-* 3.10.12-1~22.04.16 deb
Medium CVE-2026-11940 libpython3.10-* 3.10.12-1~22.04.16 deb
Medium GO-2026-4342 stdlib go1.24.6 *1.24.12, 1.25.6 go-module
Medium GO-2026-5856 stdlib (×2) go1.24.6 / go1.26.4 *1.25.12, 1.26.5, 1.27.0-rc.2 go-module
Medium GO-2026-4980 stdlib go1.24.6 *1.25.10, 1.26.3 go-module
Medium GO-2026-4976 stdlib go1.24.6 *1.25.10, 1.26.3 go-module
Medium GO-2026-5039 stdlib go1.24.6 *1.25.11, 1.26.4 go-module
Medium GO-2026-4603 stdlib go1.24.6 *1.25.8, 1.26.1 go-module
Medium GO-2026-4982 stdlib go1.24.6 *1.25.10, 1.26.3 go-module
Medium GO-2026-4864 stdlib go1.24.6 *1.25.9, 1.26.2 go-module
Medium GO-2026-4865 stdlib go1.24.6 *1.25.9, 1.26.2 go-module
Medium GO-2026-4869 stdlib go1.24.6 *1.25.9, 1.26.2 go-module
Medium GO-2025-4012 stdlib go1.24.6 *1.24.8, 1.25.2 go-module
Medium GO-2025-4015 stdlib go1.24.6 *1.24.8, 1.25.2 go-module
Medium GO-2025-4011 stdlib go1.24.6 *1.24.8, 1.25.2 go-module
Medium GO-2025-4008 stdlib go1.24.6 *1.24.8, 1.25.2 go-module
Medium GO-2025-4010 stdlib go1.24.6 *1.24.8, 1.25.2 go-module
Medium GO-2025-4014 stdlib go1.24.6 *1.24.8, 1.25.2 go-module
Medium GO-2026-4340 stdlib go1.24.6 *1.24.12, 1.25.6 go-module
Medium GO-2025-4175 stdlib go1.24.6 *1.24.11, 1.25.5 go-module
Medium CVE-2026-13221 perl* 5.34.0-3ubuntu1.7 deb
Medium CVE-2026-40355 libkrb5* 1.19.2-2ubuntu0.8 deb
Medium CVE-2026-37769 libpixman-1-0 0.40.0-1ubuntu0.22.04.1 deb
Medium CVE-2026-58016 libglib2.0-0 2.72.4-0ubuntu2.9 deb
Low CVE-2017-7189 php8.1-common / php8.1-gd / php8.1-intl 8.1.2-1ubuntu2.25 deb
Low CVE-2018-10126 libjpeg-turbo8 2.1.2-0ubuntu1 deb
Low CVE-2017-7475 libcairo2 1.16.0-5ubuntu2.1 deb
Low CVE-2018-18064 libcairo2 1.16.0-5ubuntu2.1 deb
Low CVE-2022-4899 libzstd1 1.4.8+dfsg-3build1 deb
Low CVE-2022-27943 gcc-12-base / libgcc-s1 / libstdc++6 12.3.0-1ubuntu1~22.04.3 deb
Low CVE-2023-50495 ncurses* / libtinfo6 6.3-2ubuntu0.2 deb
Low CVE-2023-31486 perl* 5.34.0-3ubuntu1.7 won't fix deb
Low CVE-2018-1000021 git / git-man 1:2.34.1-1ubuntu1.17 won't fix deb
Low CVE-2022-24975 git / git-man 1:2.34.1-1ubuntu1.17 won't fix deb
Low CVE-2024-2236 libgcrypt20 1.9.4-3ubuntu3.2 deb
Low CVE-2022-41409 libpcre2-8-0 10.39-3ubuntu0.1 deb
Low GO-2026-4602 stdlib go1.24.6 *1.25.8, 1.26.1 go-module
Negligible CVE-2020-10735 python3.10 / libpython3.10-* 3.10.12-1~22.04.16 won't fix deb
Negligible CVE-2017-11164 libpcre3 2:8.39-13ubuntu0.22.04.1 won't fix deb

(Additional medium/low entries exist; 365 total matches.)


License Findings (Grant)

Policy allows: MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISC
Status: noncompliant — 532 packages cataloged; 388 denied, 171 unlicensed

Denied/unknown license categories:

  • GPL-2.0-only (High risk) — multiple deb packages
  • GPL-2.0-or-later (High risk) — multiple deb packages
  • LGPL-2.1-or-later, LGPL-3.0-or-later (Medium risk)
  • BlueOak-1.0.0, CC-BY-3.0, CC0-1.0, curl (Unknown risk)
  • 171 packages with no license (Unknown)
  • Non-SPDX LicenseRef IDs (e.g., LicenseRef-public-domain, LicenseRef-LGPL, LicenseRef-Expat, LicenseRef-GPL, LicenseRef-permissive, LicenseRef-Artistic, LicenseRef-Boost, LicenseRef-mingw-runtime, LicenseRef-EDL-1.0, LicenseRef-TinySCHEME, LicenseRef-RFC-Reference) — unresolvable by grant

Remediation

  1. Upgrade Go runtime to at least go1.24.13 (or go1.26.5) to resolve the Critical GO-2026-4337 and all High stdlib advisories.
  2. Update or rebuild the Ubuntu 22.04 base to pick up fixes for bind9-libs, perl, python3.10, libexpat1, libglib2.0-0, libpam, libssh-4, libc.
  3. Address digest drift — re-pin the image to the current digest sha256:e39efa0edf10c0d0bfc572b59a186dfccb1973f0f77e224bcf6e5a7d81ee95c8 after validating the new image.
  4. License review — audit the 388 denied packages; strip unnecessary GPL/LGPL packages or obtain legal approval; ensure all packages carry a recognizable SPDX license identifier.

Generated by 🛡️ Daily Container Image Security Scan · sonnet46 · 65.9 AIC · ⌖ 7.3 AIC · ⊞ 4.5K ·

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions