Skip to content

[container-image-scan] Container findings for gh-aw-node #49295

Description

@github-actions

Summary

Image: ghcr.io/github/gh-aw-node
Pinned reference: ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748

Grype found 6 vulnerabilities (1 High, 5 Medium). Grant found 35 license policy violations, mostly GPL/LGPL Alpine base packages and BlueOak-1.0.0 npm packages.

Vulnerabilities

Vulnerability details (6 findings)

License policy violations

License violations (35 packages)
  • common-ancestor-path@2.0.0 — BlueOak-1.0.0
  • npm@11.18.0 — Artistic-2.0
  • zlib@1.3.2-r0 — Zlib
  • yallist@5.0.0 — BlueOak-1.0.0
  • minimatch@10.2.5 — BlueOak-1.0.0
  • busybox-binsh@1.37.0-r31 — GPL-2.0-only
  • glob@13.0.6 — BlueOak-1.0.0
  • libunistring@1.4.2-r0 — GPL-2.0-or-later, LGPL-3.0-or-later
  • musl-utils@1.2.6-r2 — GPL-2.0-or-later
  • alpine-baselayout-data@3.7.2-r1 — GPL-2.0-only
  • busybox@1.37.0-r31 — GPL-2.0-only
  • zstd-libs@1.5.7-r2 — GPL-2.0-or-later
  • minipass-flush@1.0.6 — BlueOak-1.0.0
  • minipass@7.1.3 — BlueOak-1.0.0
  • node@24.18.0 — no licenses found
  • libgcc@15.2.0-r5 — GPL-2.0-or-later, LGPL-2.1-or-later
  • alpine-baselayout@3.7.2-r1 — GPL-2.0-only
  • scanelf@1.3.9-r1 — GPL-2.0-only
  • libstdc++@15.2.0-r5 — GPL-2.0-or-later, LGPL-2.1-or-later
  • spdx-exceptions@2.5.0 — CC-BY-3.0
  • git@2.54.0-r0 — GPL-2.0-only
  • git-init-template@2.54.0-r0 — GPL-2.0-only
  • isexe@4.0.0 — BlueOak-1.0.0
  • qrcode-terminal@0.12.0 — Apache 2.0
  • tar@7.5.19 — BlueOak-1.0.0
  • lru-cache@11.5.1 — BlueOak-1.0.0
  • libcurl@8.21.0-r0 — curl
  • ca-certificates-bundle@20260611-r0 — MPL-2.0
  • path-scurry@2.0.2 — BlueOak-1.0.0
  • apk-tools@3.0.6-r0 — GPL-2.0-only
  • spdx-license-ids@3.0.23 — CC0-1.0
  • libidn2@2.3.8-r0 — GPL-2.0-or-later, LGPL-3.0-or-later
  • libapk@3.0.6-r0 — GPL-2.0-only
  • chownr@3.0.0 — BlueOak-1.0.0
  • ssl_client@1.37.0-r31 — GPL-2.0-only

Remediation

  • Rebuild the image on a newer Alpine base to pick up the patched nghttp2-libs release for CVE-2026-58055 and the fixed busybox/ssl_client builds addressing CVE-2025-60876.
  • Bump tar to ≥7.5.21 and brace-expansion to ≥5.0.8 in the npm dependency tree used by this image.
  • node@24.18.0 reports "no licenses found" — verify the correct upstream Node.js license (MIT) is captured/attached in the SBOM metadata.
  • The GPL/LGPL findings are standard Alpine base-layer packages (busybox, musl, apk-tools, libgcc, etc.); confirm the license policy intentionally treats OS base packages as exempt, or add an explicit allow-list.

Generated by 🛡️ Daily Container Image Security Scan · auto · 370.7 AIC · ⌖ 9.22 AIC · ⊞ 6.3K ·

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions