Skip to content

🚨 Security: Critical or high vulnerabilities in aws-diagram container #987

Description

@github-actions

🚨 Security Scan Alert

A periodic security scan found fixable critical or high severity vulnerabilities in the container image. Findings at this level also block publishing in the build workflow.

  • Image: ghcr.io/stacklok/dockyard/uvx/aws-diagram:1.0.23
  • Critical vulnerabilities: 0
  • High vulnerabilities: 1

Details

See the Security tab for full details.

High Vulnerabilities

  • GHSA-8xx6-hgc6-gc2m in httpx2@2.10.0: HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)

Automated security scan from periodic-security-scan workflow

Activity

  1. github-actions commented on Sep 21, 2026

    @github-actions
    ContributorAuthor

    Updated Scan Results

    🚨 Security Scan Alert

    A periodic security scan found fixable critical or high severity vulnerabilities in the container image. Findings at this level also block publishing in the build workflow.

    • Image: ghcr.io/stacklok/dockyard/uvx/aws-diagram:1.0.23
    • Critical vulnerabilities: 0
    • High vulnerabilities: 1

    Details

    See the Security tab for full details.

    High Vulnerabilities

    • GHSA-8xx6-hgc6-gc2m in httpx2@2.10.0: HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)

    Automated security scan from periodic-security-scan workflow

  2. github-actions commented on Sep 28, 2026

    @github-actions
    ContributorAuthor

    Updated Scan Results

    🚨 Security Scan Alert

    A periodic security scan found fixable critical or high severity vulnerabilities in the container image. Findings at this level also block publishing in the build workflow.

    • Image: ghcr.io/stacklok/dockyard/uvx/aws-diagram:1.0.23
    • Critical vulnerabilities: 0
    • High vulnerabilities: 1

    Details

    See the Security tab for full details.

    High Vulnerabilities

    • GHSA-8xx6-hgc6-gc2m in httpx2@2.10.0: HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)

    Automated security scan from periodic-security-scan workflow

  3. github-actions commented on Oct 5, 2026

    @github-actions
    ContributorAuthor

    Updated Scan Results

    🚨 Security Scan Alert

    A periodic security scan found fixable critical or high severity vulnerabilities in the container image. Findings at this level also block publishing in the build workflow.

    • Image: ghcr.io/stacklok/dockyard/uvx/aws-diagram:1.0.23
    • Critical vulnerabilities: 1
    • High vulnerabilities: 11

    Details

    See the Security tab for full details.

    Critical Vulnerabilities

    • GHSA-ffc3-869f-jxw9 in pyjwt@2.13.0: PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard

    High Vulnerabilities

    • GHSA-8xx6-hgc6-gc2m in httpx2@2.10.0: HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
    • GHSA-vxq7-64xx-v4gw in urllib3@2.7.0: urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory
    • GHSA-8988-9cw3-xx77 in urllib3@2.7.0: urllib3: HTTPS proxy TLS configuration may be ignored or overridden
    • GHSA-r6x4-923q-g947 in pyjwt@2.13.0: PyJWT BOM Bypass
    • GHSA-w2cx-738m-mc7w in pyjwt@2.13.0: PyJWT accepts public JWK containers as HMAC secrets

    ... and 6 more. See Security tab for complete list.


    Automated security scan from periodic-security-scan workflow

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions