Skip to content

Nightly vulnerability scan #143

Description

@github-actions

Updated 2026-10-11 01:32 UTC from the nightly scan of the published images.

Actionable — fix available (3)

Cleared by merging the automated base-image / npm update PR, or by bumping the affected package.

Severity ID Package Installed Fix
MEDIUM CVE-2026-85091 zlib 1.3.2-r0 1.3.2-r1
MEDIUM CVE-2026-85091 zlib 1.3.2-r0 1.3.2-r1
MEDIUM CVE-2026-85091 zlib 1.3.2-r0 1.3.2-r1

Awareness (11)

Tracked for visibility only, never pages the review team. See Reason for why
each one isn't gated: no upstream fix yet, or, for npm-bundled dependencies,
the fix exists in the library but npm hasn't shipped a release bundling it.

Severity ID Package Installed Fix Reason
HIGH CVE-2026-102276 brace-expansion 5.0.9 5.0.10, 3.0.7, 2.1.5, 1.1.19 npm bundles this dependency itself; needs a new npm release, not just a newer library
HIGH CVE-2026-102278 brace-expansion 5.0.9 5.0.11, 3.0.8, 2.1.6, 1.1.20 npm bundles this dependency itself; needs a new npm release, not just a newer library
HIGH CVE-2026-19534 undici 6.28.0 6.28.1, 7.29.1, 8.10.2 npm bundles this dependency itself; needs a new npm release, not just a newer library
HIGH CVE-2026-93748 http-cache-semantics 4.2.0 npm bundles this dependency itself; needs a new npm release, not just a newer library
MEDIUM CVE-2026-101910 ip-address 10.5.0 10.5.1 npm bundles this dependency itself; needs a new npm release, not just a newer library
MEDIUM CVE-2026-101911 ip-address 10.5.0 10.7.1 npm bundles this dependency itself; needs a new npm release, not just a newer library
MEDIUM CVE-2026-101912 ip-address 10.5.0 10.7.1 npm bundles this dependency itself; needs a new npm release, not just a newer library
MEDIUM CVE-2026-101913 ip-address 10.5.0 10.5.1 npm bundles this dependency itself; needs a new npm release, not just a newer library
MEDIUM CVE-2026-102277 brace-expansion 5.0.9 5.0.12, 3.0.9, 2.1.7, 1.1.21 npm bundles this dependency itself; needs a new npm release, not just a newer library
MEDIUM CVE-2026-104844 postcss-selector-parser 7.1.4 7.1.6 npm bundles this dependency itself; needs a new npm release, not just a newer library
MEDIUM CVE-2026-85024 undici 6.28.0 6.28.1, 7.29.1, 8.10.2 npm bundles this dependency itself; needs a new npm release, not just a newer library

Activity

  1. github-actions commented on Oct 8, 2026

    @github-actions
    Author

    Fixable vulnerabilities detected in the published images. cc @defra/principal-developers

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions