Summary
Image: ghcr.io/github/gh-aw-node
Pinned reference: ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748
Grype found 6 vulnerabilities (1 High, 5 Medium). Grant found 35 license policy violations, mostly GPL/LGPL Alpine base packages and BlueOak-1.0.0 npm packages.
Vulnerabilities
Vulnerability details (6 findings)
License policy violations
License violations (35 packages)
common-ancestor-path@2.0.0 — BlueOak-1.0.0
npm@11.18.0 — Artistic-2.0
zlib@1.3.2-r0 — Zlib
yallist@5.0.0 — BlueOak-1.0.0
minimatch@10.2.5 — BlueOak-1.0.0
busybox-binsh@1.37.0-r31 — GPL-2.0-only
glob@13.0.6 — BlueOak-1.0.0
libunistring@1.4.2-r0 — GPL-2.0-or-later, LGPL-3.0-or-later
musl-utils@1.2.6-r2 — GPL-2.0-or-later
alpine-baselayout-data@3.7.2-r1 — GPL-2.0-only
busybox@1.37.0-r31 — GPL-2.0-only
zstd-libs@1.5.7-r2 — GPL-2.0-or-later
minipass-flush@1.0.6 — BlueOak-1.0.0
minipass@7.1.3 — BlueOak-1.0.0
node@24.18.0 — no licenses found
libgcc@15.2.0-r5 — GPL-2.0-or-later, LGPL-2.1-or-later
alpine-baselayout@3.7.2-r1 — GPL-2.0-only
scanelf@1.3.9-r1 — GPL-2.0-only
libstdc++@15.2.0-r5 — GPL-2.0-or-later, LGPL-2.1-or-later
spdx-exceptions@2.5.0 — CC-BY-3.0
git@2.54.0-r0 — GPL-2.0-only
git-init-template@2.54.0-r0 — GPL-2.0-only
isexe@4.0.0 — BlueOak-1.0.0
qrcode-terminal@0.12.0 — Apache 2.0
tar@7.5.19 — BlueOak-1.0.0
lru-cache@11.5.1 — BlueOak-1.0.0
libcurl@8.21.0-r0 — curl
ca-certificates-bundle@20260611-r0 — MPL-2.0
path-scurry@2.0.2 — BlueOak-1.0.0
apk-tools@3.0.6-r0 — GPL-2.0-only
spdx-license-ids@3.0.23 — CC0-1.0
libidn2@2.3.8-r0 — GPL-2.0-or-later, LGPL-3.0-or-later
libapk@3.0.6-r0 — GPL-2.0-only
chownr@3.0.0 — BlueOak-1.0.0
ssl_client@1.37.0-r31 — GPL-2.0-only
Remediation
- Rebuild the image on a newer Alpine base to pick up the patched
nghttp2-libs release for CVE-2026-58055 and the fixed busybox/ssl_client builds addressing CVE-2025-60876.
- Bump
tar to ≥7.5.21 and brace-expansion to ≥5.0.8 in the npm dependency tree used by this image.
node@24.18.0 reports "no licenses found" — verify the correct upstream Node.js license (MIT) is captured/attached in the SBOM metadata.
- The GPL/LGPL findings are standard Alpine base-layer packages (busybox, musl, apk-tools, libgcc, etc.); confirm the license policy intentionally treats OS base packages as exempt, or add an explicit allow-list.
Generated by 🛡️ Daily Container Image Security Scan · auto · 370.7 AIC · ⌖ 9.22 AIC · ⊞ 6.3K · ◷
Summary
Image:
ghcr.io/github/gh-aw-nodePinned reference:
ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748Grype found 6 vulnerabilities (1 High, 5 Medium). Grant found 35 license policy violations, mostly GPL/LGPL Alpine base packages and BlueOak-1.0.0 npm packages.
Vulnerabilities
Vulnerability details (6 findings)
brace-expansion@5.0.7(fix: 5.0.8)busybox@1.37.0-r31busybox-binsh@1.37.0-r31ssl_client@1.37.0-r31nghttp2-libs@1.69.0-r0tar@7.5.19(fix: 7.5.21)License policy violations
License violations (35 packages)
common-ancestor-path@2.0.0— BlueOak-1.0.0npm@11.18.0— Artistic-2.0zlib@1.3.2-r0— Zlibyallist@5.0.0— BlueOak-1.0.0minimatch@10.2.5— BlueOak-1.0.0busybox-binsh@1.37.0-r31— GPL-2.0-onlyglob@13.0.6— BlueOak-1.0.0libunistring@1.4.2-r0— GPL-2.0-or-later, LGPL-3.0-or-latermusl-utils@1.2.6-r2— GPL-2.0-or-lateralpine-baselayout-data@3.7.2-r1— GPL-2.0-onlybusybox@1.37.0-r31— GPL-2.0-onlyzstd-libs@1.5.7-r2— GPL-2.0-or-laterminipass-flush@1.0.6— BlueOak-1.0.0minipass@7.1.3— BlueOak-1.0.0node@24.18.0— no licenses foundlibgcc@15.2.0-r5— GPL-2.0-or-later, LGPL-2.1-or-lateralpine-baselayout@3.7.2-r1— GPL-2.0-onlyscanelf@1.3.9-r1— GPL-2.0-onlylibstdc++@15.2.0-r5— GPL-2.0-or-later, LGPL-2.1-or-laterspdx-exceptions@2.5.0— CC-BY-3.0git@2.54.0-r0— GPL-2.0-onlygit-init-template@2.54.0-r0— GPL-2.0-onlyisexe@4.0.0— BlueOak-1.0.0qrcode-terminal@0.12.0— Apache 2.0tar@7.5.19— BlueOak-1.0.0lru-cache@11.5.1— BlueOak-1.0.0libcurl@8.21.0-r0— curlca-certificates-bundle@20260611-r0— MPL-2.0path-scurry@2.0.2— BlueOak-1.0.0apk-tools@3.0.6-r0— GPL-2.0-onlyspdx-license-ids@3.0.23— CC0-1.0libidn2@2.3.8-r0— GPL-2.0-or-later, LGPL-3.0-or-laterlibapk@3.0.6-r0— GPL-2.0-onlychownr@3.0.0— BlueOak-1.0.0ssl_client@1.37.0-r31— GPL-2.0-onlyRemediation
nghttp2-libsrelease for CVE-2026-58055 and the fixedbusybox/ssl_clientbuilds addressing CVE-2025-60876.tarto ≥7.5.21 andbrace-expansionto ≥5.0.8 in the npm dependency tree used by this image.node@24.18.0reports "no licenses found" — verify the correct upstream Node.js license (MIT) is captured/attached in the SBOM metadata.