Overview
Image: ghcr.io/github/gh-aw-mcpg:v0.4.9 — pinned reference:
ghcr.io/github/gh-aw-mcpg:v0.4.9@sha256:e5a1569aeaf41820fa7bdee3e94468cae448133cdbf00119ad24f5b74db1ab9f
Grype found: 5 High, 8 Medium, 6 Low, 1 Unknown (0 Critical) across 288 packages. Grant found 59 license policy violations.
Key metrics
| Severity |
Count |
| Critical |
0 |
| High |
5 |
| Medium |
8 |
| Low |
6 |
| Unknown |
1 |
High severity vulnerabilities
| CVE/Advisory |
Package |
Installed |
Fixed |
| GO-2026-5037 |
stdlib (Go) |
go1.26.3 |
1.25.11 / 1.26.4 |
| GO-2026-5970 |
golang.org/x/text |
v0.38.0 |
v0.39.0 |
| GO-2026-4970 |
stdlib (Go) |
go1.26.4 |
1.25.12 / 1.26.5 / 1.27.0-rc.2 |
| GHSA-f5mr-q85p-6hh6 |
sigstore/fulcio |
v1.8.5 |
v1.8.6 |
| GHSA-hrxh-6v49-42gf |
grpc |
v1.81.1 |
v1.82.1 |
Medium / Low / Unknown vulnerabilities
8 Medium, 6 Low, 1 Unknown findings
Additional Go-module and Alpine-base transitive advisories at lower severity. See raw scan log at /tmp/gh-aw/agent/image-scan/compile-output.txt (grep gh-aw-mcpg:v0.4.9) for full per-line detail.
License policy violations
59 rejected/unknown licenses
Mix of Alpine base package GPL/MPL licenses and Go-module vendored dependency licenses flagged as rejected/unknown by policy.
Remediation
- Rebuild Go toolchain to >=1.25.12/1.26.5 (or 1.27.0-rc.2) to resolve GO-2026-5037 and GO-2026-4970.
- Bump
golang.org/x/text to >=v0.39.0, sigstore/fulcio to >=v1.8.6, and grpc to >=v1.82.1.
- Review Grant license policy allow-list for flagged Go-module/Alpine licenses if intentionally accepted.
- Daily
--force-refresh-container-pins run is the default remediation path once the fixed base image/toolchain is published.
Generated by 🛡️ Daily Container Image Security Scan · auto · 295.8 AIC · ⌖ 10.1 AIC · ⊞ 6.9K · ◷
Overview
Image:
ghcr.io/github/gh-aw-mcpg:v0.4.9— pinned reference:ghcr.io/github/gh-aw-mcpg:v0.4.9@sha256:e5a1569aeaf41820fa7bdee3e94468cae448133cdbf00119ad24f5b74db1ab9fGrype found: 5 High, 8 Medium, 6 Low, 1 Unknown (0 Critical) across 288 packages. Grant found 59 license policy violations.
Key metrics
High severity vulnerabilities
Medium / Low / Unknown vulnerabilities
8 Medium, 6 Low, 1 Unknown findings
Additional Go-module and Alpine-base transitive advisories at lower severity. See raw scan log at
/tmp/gh-aw/agent/image-scan/compile-output.txt(grepgh-aw-mcpg:v0.4.9) for full per-line detail.License policy violations
59 rejected/unknown licenses
Mix of Alpine base package GPL/MPL licenses and Go-module vendored dependency licenses flagged as rejected/unknown by policy.
Remediation
golang.org/x/textto >=v0.39.0,sigstore/fulcioto >=v1.8.6, andgrpcto >=v1.82.1.--force-refresh-container-pinsrun is the default remediation path once the fixed base image/toolchain is published.