Overview
This is the consolidated Critical/High CVE burn-down tracker for the daily container image security scan. Per-image detail issues are linked below; this issue is the parent tracking item and intentionally does not duplicate per-image detail.
Summary table
| Image |
Critical |
High |
Total (all severities) |
Detail issue |
| ghcr.io/github/serena-mcp-server:sha-891c160 |
31 |
205 |
514+ license violations, 1129+ raw vuln rows |
#52656 |
| node:lts-alpine |
1 |
6 |
21 vulns, 29 license violations |
#aw_ltsalp |
| ghcr.io/github/github-mcp-server:v1.9.0 |
1 |
3 |
16 vulns, 6 license violations |
#52654 |
| ghcr.io/github/gh-aw-firewall/squid:0.27.44 |
0 |
14 |
22 vulns, 37 license violations |
#52652 |
| ghcr.io/github/gh-aw-firewall/agent:0.27.44 |
0 |
6 |
377 vulns, 211 license violations |
#52650 |
| ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44 |
0 |
6 |
25 vulns, 35 license violations |
#aw_fwapi |
| ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.44 |
0 |
6 |
24 vulns, 40 license violations |
#52651 |
| ghcr.io/github/gh-aw-mcpg:v0.4.9 |
0 |
5 |
20 vulns, 59 license violations |
#52653 |
| grafana/mcp-grafana:1.0.0-alpine |
0 |
1 |
4 vulns, 12 license violations |
#52655 |
| ghcr.io/github/gh-aw-node |
0 |
1 |
7 vulns, 35 license violations |
#aw_node1 |
Totals: 33 Critical, 253 High findings across 10 scanned images.
Remediation SLA
- Critical findings are remediated or explicitly risk-accepted within 7 days.
- High findings are remediated within 30 days.
- Every scanned image is rebuilt on a refreshed base image at least weekly — this workflow runs
gh aw compile --force-refresh-container-pins daily, so a pin refresh PR is the default remediation step for base-image-sourced findings.
Next actions
- Prioritize
serena-mcp-server (31 Critical / 205 High) — by far the largest remediation burden; see its detail issue for a phased remediation plan.
node:lts-alpine and github-mcp-server each carry 1 Critical finding requiring individual tracking (glibc/tar advisories, some with no upstream fix yet).
gh-aw-firewall/squid has the highest single-image High count (14) but all trace to one root cause (bind-libs/bind-tools upgrade) — quick win.
- Track this issue until all per-image Critical/High counts reach zero or are explicitly risk-accepted.
Generated by 🛡️ Daily Container Image Security Scan · auto · 295.8 AIC · ⌖ 10.1 AIC · ⊞ 6.9K · ◷
Overview
This is the consolidated Critical/High CVE burn-down tracker for the daily container image security scan. Per-image detail issues are linked below; this issue is the parent tracking item and intentionally does not duplicate per-image detail.
Summary table
Totals: 33 Critical, 253 High findings across 10 scanned images.
Remediation SLA
gh aw compile --force-refresh-container-pinsdaily, so a pin refresh PR is the default remediation step for base-image-sourced findings.Next actions
serena-mcp-server(31 Critical / 205 High) — by far the largest remediation burden; see its detail issue for a phased remediation plan.node:lts-alpineandgithub-mcp-servereach carry 1 Critical finding requiring individual tracking (glibc/tar advisories, some with no upstream fix yet).gh-aw-firewall/squidhas the highest single-image High count (14) but all trace to one root cause (bind-libs/bind-toolsupgrade) — quick win.