Skip to content

[uk-ai-resilience] Consolidate recurring gh-aw-firewall container image CVE scan issues under burn-down tracker #53417

Description

@github-actions

Tier and risk-scoring

  • Tier: B — Open With Conditions
  • Risk dimensions: Exposure amplification: Medium (sandbox is the security boundary for agent execution) · Patchability: Medium (base-image bumps, cadence-dependent) · Detectability: High (weekly scans exist) · Operational fragility: Medium (accumulating unaddressed base-image CVEs across multiple open per-version issues) · Ownership confidence: Medium (burn-down issue [container-image-scan] Container CVE burn-down #52657 exists but individual per-version issues keep proliferating)

Finding

The last 7 days of container-image-scan automation opened/kept-open numerous per-version findings for gh-aw-firewall components (agent, squid, cli-proxy, api-proxy) plus related images (mcpg, github-mcp-server, serena-mcp-server, node:lts-alpine): #53075, #53073, #53072, #53071, #52858, #52652, #52456, #52455, #51710, #51707, #51329, #51328, #51022, #51021, #51020. An aggregate burn-down tracker already exists (#52657), but individual per-scan issues continue to open without visible linkage/closure against it, risking triage drift and aging CVE backlog in the sandbox's own network-egress-control images.

Remediation action

  • Consolidate open per-version container-image-scan issues under the existing burn-down tracker [container-image-scan] Container CVE burn-down #52657 (cross-reference and close duplicates/superseded versions).
  • Confirm the gh-aw-firewall base-image bump cadence keeps pace with weekly scan frequency so CVEs don't accumulate across concurrently-open image versions.
  • Assign an explicit owner/rotation for triaging new container-image-scan issues as they land, rather than leaving them unassigned.

SLA urgency

High — this is the sandbox that isolates agentic workflow execution; unaddressed base-image CVE backlog reduces the security margin of the primary containment boundary.

Discussion report

See the full UK AI Open Code Risk & Resilience Governance discussion report for this run (created alongside this issue) for the complete asset graph, control verification, and full risk-scoring tables.

Generated by UK AI Operational Resilience · auto · 45.8 AIC · ⌖ 2.29 AIC · ⊞ 9.1K ·

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions