Skip to content

[container-image-scan] Container findings for ghcr.io/github/github-mcp-server:v1.9.0 #52654

Description

@github-actions

Overview

Image: ghcr.io/github/github-mcp-server:v1.9.0 — pinned reference:
ghcr.io/github/github-mcp-server:v1.9.0@sha256:881b53d6f75f69bdbc1b5b10fc2f1361717c19054143b3a8529fb5c32061a50e

Grype found: 1 Critical, 3 High, 3 Medium, 1 Low, 8 Negligible across 40 packages. Grant found 6 license policy violations.

Key metrics

Severity Count
Critical 1
High 3
Medium 3
Low 1
Negligible 8

Critical vulnerability

CVE Package Installed Fixed
CVE-2026-5450 libc6 2.36-9+deb12u14 (no fix listed)

High vulnerabilities

CVE/Advisory Package Installed Fixed
GO-2026-5970 golang.org/x/text v0.37.0 v0.39.0
CVE-2026-5928 libc6 2.36-9+deb12u14 (no fix listed)
CVE-2026-5435 libc6 2.36-9+deb12u14 (no fix listed)

Medium / Low / Negligible vulnerabilities

3 Medium, 1 Low, 8 Negligible findings

Remaining findings are lower-severity Debian base package (libc6 family, libssl3) advisories. See raw scan log at /tmp/gh-aw/agent/image-scan/compile-output.txt (grep github-mcp-server:v1.9.0) for full detail.

License policy violations

All 6 violations
Package Version License
base-files 12.4+deb12u15 GPL-2.0-or-later
libc6 2.36-9+deb12u14 GPL-2.0-only / HPND / LGPL-2.1-or-later / Spencer-94
netbase 6.4 GPL-2.0-only
libssl3 3.0.20-1~deb12u2 Artistic / GPL-1.0-only / GPL-1.0-or-later
media-types 10.0.0 ad-hoc
tzdata 2026b-0+deb12u1 public-domain

Remediation

  • libc6 (glibc) CVE-2026-5450/5928/5435 currently have no fixed version upstream from Debian — track for a patched libc6 release and rebuild once available; consider risk-accepting in the interim per the 7-day Critical SLA if no fix is imminent.
  • Bump golang.org/x/text to >=v0.39.0 to resolve the High GO-2026-5970 advisory (requires rebuilding the Go binary with the updated module).
  • Review Grant license policy allow-list for the 6 Debian base-package licenses (GPL/Artistic/public-domain) if intentionally accepted.
  • Daily --force-refresh-container-pins run will pick up any future glibc/Debian base patch automatically.

Generated by 🛡️ Daily Container Image Security Scan · auto · 295.8 AIC · ⌖ 10.1 AIC · ⊞ 6.9K ·

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions