Skip to content

[container-image-scan] Container findings for ghcr.io/github/gh-aw-mcpg #48149

Description

@github-actions

Summary

Image: ghcr.io/github/gh-aw-mcpg:v0.4.5@sha256:7550c5132d007266b696d77218e8d1b01f29e6e55520875b2431ef4044df71c9

Grype found 1 Critical and 13 High vulnerabilities. All critical/high findings are in Go stdlib go1.24.12 (outdated) and docker-cli.

Vulnerabilities

Critical severity (1)
CVE / ID Package Installed Fix
[GO-2026-4337]((groups.google.com/redacted) stdlib go1.24.12 1.24.13 / 1.26.0-rc.3
High severity (13)
CVE / ID Package Installed Fix
GO-2026-4981 stdlib go1.24.12 1.26.3
GO-2026-4977 stdlib go1.24.12 1.26.3
GO-2026-4986 stdlib go1.24.12 1.26.3
GO-2026-4918 stdlib go1.24.12 1.26.3
GO-2026-4601 stdlib go1.24.12 1.26.1
GO-2026-4870 stdlib go1.24.12 1.26.2
GO-2026-4947 stdlib go1.24.12 1.26.2
GO-2026-5037 stdlib go1.24.12 1.26.4
GO-2026-4971 stdlib go1.24.12 1.26.3
GO-2026-5038 stdlib go1.24.12 1.26.4
GO-2026-4946 stdlib go1.24.12 1.26.2
GO-2026-4970 stdlib go1.24.12 1.26.5
[CVE-2026-42306]((nvd.nist.gov/redacted) docker-cli 28.3.3-r5

Remediation

  • Rebuild with Go ≥1.26.5 to resolve all Go stdlib vulnerabilities.
  • Update docker-cli when a patched Alpine package is available.

Generated by 🛡️ Daily Container Image Security Scan · sonnet46 · 161.6 AIC · ⌖ 6.65 AIC · ⊞ 4.5K ·

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions