🔍 Static Analysis Report - 2026-08-15
Analysis Summary
- Tools Used: zizmor, poutine, actionlint, runner-guard, syft, grype, yamllint, shellcheck
- Total Findings: 1,805 (excluding SBOM inventory)
- Workflows Scanned: 285 (285 succeeded, 0 failed)
- Workflows Affected (by the 7 finding-producing tools): 21 of 285
- Compiler-level warnings (separate from the 8 tools): 188 total (41 distinct message instances across ~30 workflows — template-separator style, missing-permission,
/tmp/ reference, etc.)
Findings by Tool
| Tool |
Total |
Critical |
High |
Medium |
Low |
| zizmor (security) |
9 |
0 |
0 |
0 |
8 note + 1 warning |
| poutine (supply chain) |
0 |
0 |
0 |
0 |
0 |
| actionlint (linting) |
0 |
- |
- |
- |
- |
| runner-guard (taint analysis) |
122 |
0 |
111 |
11 |
0 |
| syft (SBOM inventory) |
10 images / 4,298 packages |
- |
- |
- |
- |
| grype (container CVEs) |
1,674 |
67 |
433 |
774 |
167 low + 142 negligible + 91 unknown |
| yamllint (yaml linting) |
0 |
- |
- |
- |
- |
| shellcheck (shell linting) |
0 |
- |
- |
- |
- |
Clustered Findings by Tool and Type
Zizmor Security Findings
| Issue Type |
Severity |
Count |
Affected Workflows |
github_action_from_unverified_creator_used |
Note |
8 |
smoke-codex.lock.yml, copilot-setup-steps.yml, daily-elixir-credo-snippet-audit.lock.yml, link-check.yml (×2), dataflow-pr-discussion-dataset.lock.yml, hippo-embed.lock.yml, super-linter.lock.yml |
pr_runs_on_self_hosted |
Warning |
1 |
smoke-copilot-arm.lock.yml |
All 8 unverified_creator_used sites already carry a # zizmor: ignore[...] suppression comment in source — they still surface in the compiled .lock.yml because zizmor scans the compiled output where the comment sits one line above the uses: step; these are accepted/reviewed, not new risk.
Poutine Supply Chain Findings
No findings — 0 issues detected by poutine across all 285 workflows.
Actionlint Linting Issues
No findings — actionlint reports "✓ Checked 285 workflow(s), ✓ No issues found."
Syft SBOM Inventory
| Image |
Packages |
Notes |
| ghcr.io/github/serena-mcp-server:sha-891c160 |
2,314 |
Largest image by far; Debian-trixie based; unchanged digest for 5+ days |
| ghcr.io/github/gh-aw-firewall/agent:0.28.1 |
532 |
Version bumped from 0.27.44 this run |
| ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.1 |
348 |
Version bumped from 0.27.44 this run |
| ghcr.io/github/gh-aw-mcpg:v0.4.9 |
288 |
|
| ghcr.io/github/gh-aw-firewall/api-proxy:0.28.1 |
193 |
Version bumped from 0.27.44 this run |
| ghcr.io/github/gh-aw-node |
177 |
|
| grafana/mcp-grafana:1.0.0-alpine |
178 |
|
| node:lts-alpine |
165 |
|
| ghcr.io/github/gh-aw-firewall/squid:0.28.1 |
63 |
Version bumped from 0.27.44 this run |
| ghcr.io/github/github-mcp-server:v1.9.0 |
40 |
|
These are shared engine/firewall infrastructure images used across the agentic-workflow fleet rather than images tied to one specific .md workflow source.
Runner-Guard Taint Analysis Findings
122 findings, unchanged in rule/count/workflow breakdown for the 4th consecutive scan (2026-08-12 → 2026-08-15).
| Rule ID |
Name |
Severity |
Count |
Affected Workflows |
| RGS-004 |
Comment-Triggered Workflow Without Author Authorization Check |
High |
98 |
dev-hawk.lock.yml |
| RGS-012 |
Secret Exfiltration via Outbound HTTP Request |
High |
9 |
daily-model-inventory.lock.yml, daily-byok-ollama-test.lock.yml, docs-noob-tester.lock.yml, visual-regression-checker.lock.yml |
| RGS-018 |
Suspicious Payload Execution Pattern |
High |
4 |
daily-byok-ollama-test.lock.yml, daily-cli-performance.lock.yml, daily-sentrux-report.lock.yml, smoke-claude.lock.yml |
| RGS-005 |
Excessive Permissions on Untrusted Trigger |
Medium |
9 |
ai-moderator.lock.yml, q.lock.yml, agentic_commands.yml |
| RGS-019 |
Step Output Interpolated in run Block |
Medium |
2 |
windows-cli-integration.yml, error-message-lint.yml |
Issues created: none. Every Critical/High rule+file combination eligible for filing (RGS-004/dev-hawk, RGS-012 ×4, RGS-018 ×4 — 9 combos total) already has a closed issue on file (#50189, #51943, #51944, #50190, #51945, #35653, #47478, #46532, #47477), verified today via gh api search/issues?q=...state:open returning zero open matches. Per the dedup policy, closed dups are skipped rather than recreated.
Likely false positive confirmed: I directly inspected dev-hawk.lock.yml:127-131 (source of the 98 RGS-004 hits). The activation job's if: condition already checks github.event.workflow_run.actor.login against an explicit 9-name maintainer allowlist, plus fork/repository-id checks — a genuine author-authorization gate, just not expressed as an author_association check, which is the specific shape RGS-004's detector looks for. This is almost certainly why 12+ prior issues for this rule+file closed without a code change landing.
Grype Container Vulnerability Findings
| Package family |
Severity |
Approx. count (Critical+High) |
Dominant image |
Go stdlib / golang-1.24-go / golang-1.24-src |
High |
107 |
serena-mcp-server, github-mcp-server, gh-aw-mcpg |
openssl / libssl3t64 / libssl-dev / openssl-provider-legacy |
Critical/High |
60 |
serena-mcp-server |
libcurl3t64-gnutls |
Critical |
14 |
serena-mcp-server |
perl / libperl5.40 / perl-base / perl-modules-5.40 |
Critical |
48 |
serena-mcp-server |
nodejs / libnode115 / libnode-dev |
Critical |
36 |
serena-mcp-server |
32 distinct CVE/GHSA/GO identifiers account for the 67 critical findings; 65 of the 67 criticals (and 1,154 of all 1,674 grype findings) are in a single image: ghcr.io/github/serena-mcp-server:sha-891c160, a heavy (2,314-package) Debian-trixie based image whose digest hasn't changed across any of the last 5 scans.
All grype findings by image and severity
| Image |
Critical |
High |
Medium |
Low |
Negligible |
Unknown |
| ghcr.io/github/serena-mcp-server:sha-891c160 |
65 |
395 |
423 |
96 |
115 |
60 |
| ghcr.io/github/gh-aw-firewall/agent:0.28.1 |
0 |
5 |
291 |
62 |
19 |
6 |
| ghcr.io/github/gh-aw-mcpg:v0.4.9 |
0 |
11 |
8 |
6 |
0 |
14 |
| ghcr.io/github/github-mcp-server:v1.9.0 |
1 |
4 |
3 |
1 |
8 |
5 |
| ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.1 |
0 |
5 |
10 |
0 |
0 |
6 |
| ghcr.io/github/gh-aw-firewall/api-proxy:0.28.1 |
0 |
3 |
11 |
0 |
0 |
0 |
| node:lts-alpine |
1 |
6 |
12 |
2 |
0 |
0 |
| ghcr.io/github/gh-aw-node |
0 |
1 |
9 |
0 |
0 |
0 |
| grafana/mcp-grafana:1.0.0-alpine |
0 |
3 |
3 |
0 |
0 |
0 |
| ghcr.io/github/gh-aw-firewall/squid:0.28.1 |
0 |
0 |
4 |
0 |
0 |
0 |
Yamllint YAML Linting Findings
No findings — 0 issues across 285 files.
Shellcheck Shell Linting Findings
No findings — 0 issues across all run steps in 285 files.
Top Priority Issues
1. serena-mcp-server critical/high CVE volume
- Tool: grype
- Count: 460 (65 critical + 395 high)
- Severity: Critical/High
- Affected: ghcr.io/github/serena-mcp-server:sha-891c160 (shared Serena MCP server image)
- Description: A 2,314-package Debian-trixie image carrying long-unpatched OpenSSL, libcurl, Perl, Node.js, and Go stdlib CVEs. Digest unchanged across 5+ consecutive scans.
- Impact: Largest single source of container vulnerability exposure in the fleet (69% of all grype findings). Any workflow that runs this MCP server inherits the full CVE surface.
- Reference: https://github.com/github/gh-aw
2. RGS-004: Comment-Triggered Workflow Without Author Authorization Check
- Tool: runner-guard
- Count: 98 (single file)
- Severity: High
- Affected: dev-hawk.lock.yml
- Description: Rule flags
workflow_run-triggered jobs with secrets/write access lacking an author_association check.
- Impact: Likely a scanner false positive here — the job already gates on an explicit actor-login allowlist (see investigation above). Real-world risk is low, but the recurring high-severity flag creates noise and could mask a genuine future issue if maintainers stop reviewing it.
- Reference: https://github.com/Vigilant-LLC/runner-guard
3. RGS-012: Secret Exfiltration via Outbound HTTP Request
- Tool: runner-guard
- Count: 9
- Severity: High
- Affected: daily-model-inventory.lock.yml, daily-byok-ollama-test.lock.yml, docs-noob-tester.lock.yml, visual-regression-checker.lock.yml
- Description:
run: steps issue outbound HTTP requests (curl/wget) to non-GitHub domains from jobs with secrets access.
- Impact: Several instances are documented as intentional (public model index downloads, localhost readiness probes with
runner-guard:ignore comments) but not all sites carry a suppression comment/justification yet.
- Reference: https://github.com/Vigilant-LLC/runner-guard
Fix Suggestion for RGS-012 (Secret Exfiltration via Outbound HTTP Request)
Issue: Outbound HTTP request in a run: block from a job with secrets access, without an explicit suppression/justification
Severity: High
Affected Workflows: 4 workflows, 9 sites
Prompt to Copilot Agent:
You are fixing a security finding identified by runner-guard (rule RGS-012: Secret
Exfiltration via Outbound HTTP Request).
Vulnerability: A `run:` block issues an outbound HTTP request (curl, wget, node fetch, etc.)
to a domain other than github.com / api.github.com / ghcr.io, inside a job that has access to
secrets or publishing capabilities. This pattern is the primary mechanism attackers use to
exfiltrate stolen credentials once they achieve code execution in a CI runner (e.g. via
expression injection or a compromised action).
Why it matters: even a legitimate outbound call (downloading a public index, polling a local
dev server) is indistinguishable to the scanner from credential exfiltration unless it's
either restricted to a safe/allowlisted domain, stripped of secrets, or explicitly reviewed
and annotated as safe.
Required fix, for each flagged `run:` step:
1. Confirm the destination domain and payload: does the request send any `secrets.*` or
`env.*` value in the URL, headers, or body? If yes, remove the secret from the request —
this is a real vulnerability, not a false positive.
2. If the request is safe (public read-only GET, loopback/localhost probe, no secrets in the
request), add a `# runner-guard:ignore RGS-012 -- <reason>` comment directly above the
`run:` step explaining why it's safe, mirroring the existing pattern already used in
daily-rendering-scripts-verifier.md and daily-model-inventory.md for their loopback checks.
3. If the job doesn't need secrets for this step, consider moving the HTTP call to a job (or
step) with reduced `permissions:` / no secret exposure, so the taint path the rule is
detecting no longer exists.
4. Recompile and confirm runner-guard no longer flags RGS-012 for the updated site (or that
the ignore comment suppresses it with a clear justification on record).
Example:
Before (no justification, scanner cannot distinguish from exfiltration):
```yaml
- name: Fetch model index
run: curl -fsS (models.dev/redacted) -o "$OUT/api.json"
After (annotated as a reviewed, safe, non-secret-bearing request):
- name: Fetch model index
# runner-guard:ignore RGS-012 -- unauthenticated GET from a public read-only model index; no secrets are sent.
run: curl -fsS (models.dev/redacted) -o "$OUT/api.json"
Please apply this review to the 9 flagged sites across: .github/workflows/daily-model-inventory.md,
.github/workflows/daily-byok-ollama-test.md, .github/workflows/docs-noob-tester.md,
.github/workflows/visual-regression-checker.md (source files for the flagged .lock.yml outputs).
**Reference**: https://github.com/Vigilant-LLC/runner-guard (rule does not publish a standalone docs page beyond the finding description)
### All Findings Details
<details>
<summary><b>Detailed Findings by Workflow</b></summary>
#### dev-hawk.lock.yml
- **RGS-004** (High) × 98 — Comment-Triggered Workflow Without Author Authorization Check. Closed dup of #50189. Likely false positive — actor allowlist gate confirmed present at lines 127-131.
#### daily-model-inventory.lock.yml
- **RGS-012** (High) × 4 — Secret Exfiltration via Outbound HTTP Request. Closed dup of #51943.
#### daily-byok-ollama-test.lock.yml
- **RGS-012** (High) × 2 — Closed dup of #51944.
- **RGS-018** (High) × 1 — Suspicious Payload Execution Pattern. Closed dup of #35653.
#### docs-noob-tester.lock.yml
- **RGS-012** (High) × 1 — Closed dup of #50190.
#### visual-regression-checker.lock.yml
- **RGS-012** (High) × 2 — Closed dup of #51945.
#### daily-cli-performance.lock.yml
- **RGS-018** (High) × 1 — Closed dup of #47478.
#### daily-sentrux-report.lock.yml
- **RGS-018** (High) × 1 — Closed dup of #46532.
#### smoke-claude.lock.yml
- **RGS-018** (High) × 1 — Closed dup of #47477.
#### ai-moderator.lock.yml
- **RGS-005** (Medium) × 5 — Excessive Permissions on Untrusted Trigger.
#### q.lock.yml
- **RGS-005** (Medium) × 3.
#### agentic_commands.yml
- **RGS-005** (Medium) × 1.
#### windows-cli-integration.yml
- **RGS-019** (Medium) × 1 — Step Output Interpolated in run Block.
#### error-message-lint.yml
- **RGS-019** (Medium) × 1.
#### Zizmor note/warning sites
- smoke-codex.lock.yml:2351, copilot-setup-steps.yml:42, daily-elixir-credo-snippet-audit.lock.yml:448, link-check.yml:37 & :46, dataflow-pr-discussion-dataset.lock.yml:503, hippo-embed.lock.yml:432, super-linter.lock.yml:1757 — `github_action_from_unverified_creator_used` (Note, all suppressed in source).
- smoke-copilot-arm.lock.yml:460 — `pr_runs_on_self_hosted` (Warning).
</details>
### Historical Trends
- **Previous Scan**: 2026-08-14 (run [§31772315141](https://github.com/github/gh-aw/actions/runs/31772315141))
- **Total Findings Then**: 1,780
- **Total Findings Now**: 1,805
- **Change**: +25 (+1.4%), driven entirely by grype (1,649 → 1,674); zizmor, poutine, actionlint, runner-guard, yamllint, and shellcheck are all unchanged.
#### New Issues
None. No new rule IDs, workflows, or issue types appeared today.
#### Resolved Issues
None outstanding — RGS-004/012/018 continue to recur daily as closed-issue dups (no code changes have landed for any of the 9 tracked rule+file combos across at least 5 days).
#### Notable trend
`gh-aw-firewall` images (agent/api-proxy/cli-proxy/squid) were bumped from `0.27.44` to `0.28.1` in this run, reshuffling per-image grype counts (squid 22→4, api-proxy 25→14, cli-proxy 24→21, agent 377→383) without a material change in total OS CVE exposure. `serena-mcp-server:sha-891c160` has not changed digest in 5+ days and remains responsible for 69% of all grype findings and 97% of criticals — it is the single highest-leverage target for reducing container vulnerability count fleet-wide.
### Recommendations
1. **Immediate**: None of today's Critical/High runner-guard findings require new action — all 9 rule+file combos are already tracked in closed issues. Recommend a maintainer review whether #50189 (RGS-004/dev-hawk) should be reopened with a note that it's likely a detector false positive, or whether the rule itself should be tuned to also accept actor-login-allowlist checks as a valid authorization gate.
2. **Short-term**: Review and annotate (or fix) the 9 RGS-012 outbound-HTTP sites per the fix prompt above — several already have `runner-guard:ignore` justification comments nearby, but not all 9 flagged lines do.
3. **Long-term**: Rebuild/replace `ghcr.io/github/serena-mcp-server:sha-891c160` — a newer upstream base image would likely resolve the bulk of the 67 criticals and 433 highs in one move, given the image hasn't been refreshed in 5+ tracked days.
4. **Prevention**: Continue tracking image digest changes in cache memory to distinguish "new CVE disclosed against pinned digest" from "image actually updated" — today's gh-aw-firewall version bump was a useful example of the latter.
### Next Steps
- [ ] Maintainer decision on RGS-004/dev-hawk: reopen #50189 with a false-positive note, or tune the runner-guard rule to recognize actor-allowlist gates
- [ ] Annotate remaining un-suppressed RGS-012 sites with `runner-guard:ignore` + justification, or fix genuine secret-bearing requests
- [ ] Evaluate refreshing `serena-mcp-server` base image to cut critical/high CVE count
- [ ] No actionlint/yamllint/shellcheck/poutine work needed this cycle — all clean
- [ ] Continue daily trend tracking in cache memory
**References:**
- [§31865340223](https://github.com/github/gh-aw/actions/runs/31865340223) (this scan)
- [§31772315141](https://github.com/github/gh-aw/actions/runs/31772315141) (2026-08-14 scan)
> Generated by [📊 Static Analysis Report](https://github.com/github/gh-aw/actions/runs/31865340223) · agent · 183 AIC · ⌖ 6.26 AIC · ⊞ 11K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fstatic-analysis-report%22&type=issues)
> - [x] expires <!-- gh-aw-expires: 2026-08-22T05:17:59.634Z --> on Aug 21, 2026, 9:17 PM UTC-08:00
<!-- gh-aw-agentic-workflow: Static Analysis Report, engine: claude, model: agent, id: 31865340223, workflow_id: static-analysis-report, run: https://github.com/github/gh-aw/actions/runs/31865340223 -->
<!-- gh-aw-workflow-id: static-analysis-report -->
<!-- gh-aw-workflow-call-id: github/gh-aw/static-analysis-report -->
🔍 Static Analysis Report - 2026-08-15
Analysis Summary
/tmp/reference, etc.)Findings by Tool
Clustered Findings by Tool and Type
Zizmor Security Findings
github_action_from_unverified_creator_usedpr_runs_on_self_hostedAll 8
unverified_creator_usedsites already carry a# zizmor: ignore[...]suppression comment in source — they still surface in the compiled.lock.ymlbecause zizmor scans the compiled output where the comment sits one line above theuses:step; these are accepted/reviewed, not new risk.Poutine Supply Chain Findings
No findings — 0 issues detected by poutine across all 285 workflows.
Actionlint Linting Issues
No findings — actionlint reports "✓ Checked 285 workflow(s), ✓ No issues found."
Syft SBOM Inventory
These are shared engine/firewall infrastructure images used across the agentic-workflow fleet rather than images tied to one specific
.mdworkflow source.Runner-Guard Taint Analysis Findings
122 findings, unchanged in rule/count/workflow breakdown for the 4th consecutive scan (2026-08-12 → 2026-08-15).
Issues created: none. Every Critical/High rule+file combination eligible for filing (RGS-004/dev-hawk, RGS-012 ×4, RGS-018 ×4 — 9 combos total) already has a closed issue on file (#50189, #51943, #51944, #50190, #51945, #35653, #47478, #46532, #47477), verified today via
gh api search/issues?q=...state:openreturning zero open matches. Per the dedup policy, closed dups are skipped rather than recreated.Likely false positive confirmed: I directly inspected
dev-hawk.lock.yml:127-131(source of the 98 RGS-004 hits). Theactivationjob'sif:condition already checksgithub.event.workflow_run.actor.loginagainst an explicit 9-name maintainer allowlist, plus fork/repository-id checks — a genuine author-authorization gate, just not expressed as anauthor_associationcheck, which is the specific shape RGS-004's detector looks for. This is almost certainly why 12+ prior issues for this rule+file closed without a code change landing.Grype Container Vulnerability Findings
stdlib/golang-1.24-go/golang-1.24-srcopenssl/libssl3t64/libssl-dev/openssl-provider-legacylibcurl3t64-gnutlsperl/libperl5.40/perl-base/perl-modules-5.40nodejs/libnode115/libnode-dev32 distinct CVE/GHSA/GO identifiers account for the 67 critical findings; 65 of the 67 criticals (and 1,154 of all 1,674 grype findings) are in a single image:
ghcr.io/github/serena-mcp-server:sha-891c160, a heavy (2,314-package) Debian-trixie based image whose digest hasn't changed across any of the last 5 scans.All grype findings by image and severity
Yamllint YAML Linting Findings
No findings — 0 issues across 285 files.
Shellcheck Shell Linting Findings
No findings — 0 issues across all run steps in 285 files.
Top Priority Issues
1. serena-mcp-server critical/high CVE volume
2. RGS-004: Comment-Triggered Workflow Without Author Authorization Check
workflow_run-triggered jobs with secrets/write access lacking anauthor_associationcheck.3. RGS-012: Secret Exfiltration via Outbound HTTP Request
run:steps issue outbound HTTP requests (curl/wget) to non-GitHub domains from jobs with secrets access.runner-guard:ignorecomments) but not all sites carry a suppression comment/justification yet.Fix Suggestion for RGS-012 (Secret Exfiltration via Outbound HTTP Request)
Issue: Outbound HTTP request in a
run:block from a job with secrets access, without an explicit suppression/justificationSeverity: High
Affected Workflows: 4 workflows, 9 sites
Prompt to Copilot Agent:
After (annotated as a reviewed, safe, non-secret-bearing request):
Please apply this review to the 9 flagged sites across: .github/workflows/daily-model-inventory.md,
.github/workflows/daily-byok-ollama-test.md, .github/workflows/docs-noob-tester.md,
.github/workflows/visual-regression-checker.md (source files for the flagged .lock.yml outputs).