Skip to content

[container-image-scan] Container CVE burn-down #52657

Description

@github-actions

Overview

This is the consolidated Critical/High CVE burn-down tracker for the daily container image security scan. Per-image detail issues are linked below; this issue is the parent tracking item and intentionally does not duplicate per-image detail.

Summary table

Image Critical High Total (all severities) Detail issue
ghcr.io/github/serena-mcp-server:sha-891c160 31 205 514+ license violations, 1129+ raw vuln rows #52656
node:lts-alpine 1 6 21 vulns, 29 license violations #aw_ltsalp
ghcr.io/github/github-mcp-server:v1.9.0 1 3 16 vulns, 6 license violations #52654
ghcr.io/github/gh-aw-firewall/squid:0.27.44 0 14 22 vulns, 37 license violations #52652
ghcr.io/github/gh-aw-firewall/agent:0.27.44 0 6 377 vulns, 211 license violations #52650
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44 0 6 25 vulns, 35 license violations #aw_fwapi
ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.44 0 6 24 vulns, 40 license violations #52651
ghcr.io/github/gh-aw-mcpg:v0.4.9 0 5 20 vulns, 59 license violations #52653
grafana/mcp-grafana:1.0.0-alpine 0 1 4 vulns, 12 license violations #52655
ghcr.io/github/gh-aw-node 0 1 7 vulns, 35 license violations #aw_node1

Totals: 33 Critical, 253 High findings across 10 scanned images.

Remediation SLA

  • Critical findings are remediated or explicitly risk-accepted within 7 days.
  • High findings are remediated within 30 days.
  • Every scanned image is rebuilt on a refreshed base image at least weekly — this workflow runs gh aw compile --force-refresh-container-pins daily, so a pin refresh PR is the default remediation step for base-image-sourced findings.

Next actions

  • Prioritize serena-mcp-server (31 Critical / 205 High) — by far the largest remediation burden; see its detail issue for a phased remediation plan.
  • node:lts-alpine and github-mcp-server each carry 1 Critical finding requiring individual tracking (glibc/tar advisories, some with no upstream fix yet).
  • gh-aw-firewall/squid has the highest single-image High count (14) but all trace to one root cause (bind-libs/bind-tools upgrade) — quick win.
  • Track this issue until all per-image Critical/High counts reach zero or are explicitly risk-accepted.

Generated by 🛡️ Daily Container Image Security Scan · auto · 295.8 AIC · ⌖ 10.1 AIC · ⊞ 6.9K ·

Metadata

Metadata

Assignees

No one assigned

    Labels

    cookieIssue Monster Loves Cookies!security

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions