Summary
Image: ghcr.io/github/github-mcp-server:v1.9.0@sha256:881b53d6f75...
1 Critical, 3 High, 3 Medium, 1 Low, 7 Negligible vulnerabilities; 6 license policy violations.
Remediation
- Rebase on a newer Debian 12 point release / bump
libc6 and libssl3 to pick up glibc and OpenSSL security patches.
- Update
golang.org/x/text to >= 0.39.0 to fix GO-2026-5970.
- Review GPL-2.0/Artistic-licensed base packages (
libssl3, libc6, netbase, base-files) and the no licenses found/ad-hoc/public-domain items (tzdata, media-types) against the license policy; add explicit exceptions for unavoidable base-OS packages if acceptable.
Vulnerabilities
13 vulnerabilities across libc6, libssl3, golang.org/x/text
License Violations
6 rejected/unknown licenses
| Package |
Version |
License(s) |
| tzdata |
2026b-0+deb12u1 |
public-domain |
| netbase |
6.4 |
GPL-2.0-only |
| libssl3 |
3.0.20-1~deb12u2 |
Artistic, GPL-1.0-only, GPL-1.0-or-later |
| media-types |
10.0.0 |
ad-hoc |
| libc6 |
2.36-9+deb12u14 |
GPL-2.0-only, HPND, LGPL-2.1-or-later, Spencer-94 |
| base-files |
12.4+deb12u15 |
GPL-2.0-or-later |
Generated by 🛡️ Daily Container Image Security Scan · auto · 327.5 AIC · ⌖ 10.6 AIC · ⊞ 6.5K · ◷
Summary
Image:
ghcr.io/github/github-mcp-server:v1.9.0@sha256:881b53d6f75...1 Critical, 3 High, 3 Medium, 1 Low, 7 Negligible vulnerabilities; 6 license policy violations.
Remediation
libc6andlibssl3to pick up glibc and OpenSSL security patches.golang.org/x/textto >= 0.39.0 to fix GO-2026-5970.libssl3,libc6,netbase,base-files) and theno licenses found/ad-hoc/public-domainitems (tzdata,media-types) against the license policy; add explicit exceptions for unavoidable base-OS packages if acceptable.Vulnerabilities
13 vulnerabilities across libc6, libssl3, golang.org/x/text
License Violations
6 rejected/unknown licenses