Skip to content

[container-image-scan] Container findings for ghcr.io/github/gh-aw-mcpg:v0.4.9 #52653

Description

@github-actions

Overview

Image: ghcr.io/github/gh-aw-mcpg:v0.4.9 — pinned reference:
ghcr.io/github/gh-aw-mcpg:v0.4.9@sha256:e5a1569aeaf41820fa7bdee3e94468cae448133cdbf00119ad24f5b74db1ab9f

Grype found: 5 High, 8 Medium, 6 Low, 1 Unknown (0 Critical) across 288 packages. Grant found 59 license policy violations.

Key metrics

Severity Count
Critical 0
High 5
Medium 8
Low 6
Unknown 1

High severity vulnerabilities

CVE/Advisory Package Installed Fixed
GO-2026-5037 stdlib (Go) go1.26.3 1.25.11 / 1.26.4
GO-2026-5970 golang.org/x/text v0.38.0 v0.39.0
GO-2026-4970 stdlib (Go) go1.26.4 1.25.12 / 1.26.5 / 1.27.0-rc.2
GHSA-f5mr-q85p-6hh6 sigstore/fulcio v1.8.5 v1.8.6
GHSA-hrxh-6v49-42gf grpc v1.81.1 v1.82.1

Medium / Low / Unknown vulnerabilities

8 Medium, 6 Low, 1 Unknown findings

Additional Go-module and Alpine-base transitive advisories at lower severity. See raw scan log at /tmp/gh-aw/agent/image-scan/compile-output.txt (grep gh-aw-mcpg:v0.4.9) for full per-line detail.

License policy violations

59 rejected/unknown licenses

Mix of Alpine base package GPL/MPL licenses and Go-module vendored dependency licenses flagged as rejected/unknown by policy.

Remediation

  • Rebuild Go toolchain to >=1.25.12/1.26.5 (or 1.27.0-rc.2) to resolve GO-2026-5037 and GO-2026-4970.
  • Bump golang.org/x/text to >=v0.39.0, sigstore/fulcio to >=v1.8.6, and grpc to >=v1.82.1.
  • Review Grant license policy allow-list for flagged Go-module/Alpine licenses if intentionally accepted.
  • Daily --force-refresh-container-pins run is the default remediation path once the fixed base image/toolchain is published.

Generated by 🛡️ Daily Container Image Security Scan · auto · 295.8 AIC · ⌖ 10.1 AIC · ⊞ 6.9K ·

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions