Skip to content

[uk-ai-resilience] [security] Upgrade Go runtime in gh-aw-firewall/agent container — critical GO-2026-4337 (Tier C) #47821

Description

@github-actions

🔴 Critical — Tier C: Restricted Pending Review

Source: UK AI Open Code Risk & Resilience Governance — weekly scan 2026-07-24
SLA: 3 days (by 2026-07-27)

Finding

The ghcr.io/github/gh-aw-firewall/agent:0.27.41 container image uses Go go1.24.6, which is affected by a critical vulnerability:

ID Severity Package Fixed In
GO-2026-4337 🔴 Critical stdlib go1.24.6 ≥go1.24.13, 1.25.7, 1.26.0-rc.3

Additionally there are 18 high-severity stdlib advisories all fixed by upgrading to go1.24.12+ or go1.25.6+. Total: 365 CVEs in the image (1 critical, 43 fixable). Digest drift also detected.

Risk Scoring

Dimension Score (1–5) Notes
Exposure amplification 5 Critical stdlib CVE in production agent runtime
Patchability 4 Go toolchain upgrade; straightforward
Detectability 4 Grype detects; exploit may be subtle
Operational fragility 4 Agent container is core agentic runtime
Ownership confidence 4 pelikhan owns firewall versioning
Overall Tier C Restricted Pending Review

Remediation Actions

  1. Upgrade Go runtime in firewall agent Dockerfile to ≥go1.24.13 (or go1.25.7+).
  2. Rebuild ghcr.io/github/gh-aw-firewall/agent with updated Go toolchain.
  3. Re-pin actions-lock.json / container pin entries to new image digest after validation.
  4. Update DefaultFirewallVersion in gh-aw if a new firewall release is cut.

Exception Governance

  • Threat hypothesis: Exploitation of GO-2026-4337 via malicious input to the agent runtime
  • Operational weakness: No patch applied; image in active use
  • Expiry date: 2026-07-27
  • Mitigation plan: Upgrade Go runtime → rebuild → re-pin

Governance report: UK AI Open Code Risk & Resilience Governance — Weekly Report 2026-07-24

References: §30107107922 · Container scan issue #47737

Generated by UK AI Operational Resilience · sonnet46 · 66.3 AIC · ⌖ 8.85 AIC · ⊞ 5.3K ·

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions