Skip to content

[WIP] Fix vulnerabilities in container image gh-aw-mcpg - #52049

Closed
pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/container-image-scan-gh-aw-mcpg
Closed

pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/container-image-scan-gh-aw-mcpg

Conversation

Copilot AI commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Thanks for asking me to work on this. I will get started on it and keep this PR's description up to date as I form a plan and make progress.


This section details on the original issue you should resolve

<issue_title>[container-image-scan] Container findings for gh-aw-mcpg</issue_title>
<issue_description>### Summary

  • Image: ghcr.io/github/gh-aw-mcpg:v0.4.9@sha256:e5a1569aeaf41820fa7bdee3e94468cae448133cdbf00119ad24f5b74db1ab9f
  • Vulnerabilities: 20 total (Critical: 0, High: 5, Medium: 8, Low: 6, Negligible: 0, Unknown: 1)
  • License violations: 59

Vulnerabilities

All 20 vulnerabilities (severity, CVE/advisory ID, package@version, fixed version)

[High] GHSA-f5mr-q85p-6hh6: github.com/sigstore/fulcio@v1.8.5 (fix: 1.8.6) (GHSA-f5mr-q85p-6hh6)
[High] GHSA-hrxh-6v49-42gf: google.golang.org/grpc@v1.81.1 (fix: 1.82.1) (GHSA-hrxh-6v49-42gf)
[High] GO-2026-4970: stdlib@go1.26.4 (fix: 1.25.12, 1.26.5, 1.27.0-rc.2) (https://go.dev/issue/79005)
[High] GO-2026-5037: stdlib@go1.26.3 (fix: 1.25.11, 1.26.4) (https://go.dev/cl/783621)
[High] GO-2026-5970: golang.org/x/text@v0.38.0 (fix: 0.39.0) (https://go.dev/issue/80142)
[Low] CVE-2022-3219: gnupg-dirmngr@2.4.9-r1 ((nvd.nist.gov/redacted)
[Low] CVE-2022-3219: gnupg-gpgconf@2.4.9-r1 ((nvd.nist.gov/redacted)
[Low] CVE-2022-3219: gnupg-keyboxd@2.4.9-r1 ((nvd.nist.gov/redacted)
[Low] CVE-2022-3219: gpg-agent@2.4.9-r1 ((nvd.nist.gov/redacted)
[Low] CVE-2022-3219: gpg@2.4.9-r1 ((nvd.nist.gov/redacted)
[Low] CVE-2022-3219: gpgsm@2.4.9-r1 ((nvd.nist.gov/redacted)
[Medium] CVE-2025-60876: busybox-binsh@1.37.0-r31 ((nvd.nist.gov/redacted)
[Medium] CVE-2025-60876: busybox@1.37.0-r31 ((nvd.nist.gov/redacted)
[Medium] CVE-2025-60876: ssl_client@1.37.0-r31 ((nvd.nist.gov/redacted)
[Medium] GHSA-xjvp-4fhw-gc47: github.com/opencontainers/runc@v1.4.2 (fix: 1.4.3) (GHSA-xjvp-4fhw-gc47)
[Medium] GO-2026-5039: stdlib@go1.26.3 (fix: 1.25.11, 1.26.4) (https://go.dev/issue/79346)
[Medium] GO-2026-5856: stdlib@go1.26.3 (fix: 1.25.12, 1.26.5, 1.27.0-rc.2) (https://go.dev/cl/775960)
[Medium] GO-2026-5856: stdlib@go1.26.4 (fix: 1.25.12, 1.26.5, 1.27.0-rc.2) (https://go.dev/cl/775960)
[Medium] GO-2026-5856: stdlib@go1.26.4 (fix: 1.25.12, 1.26.5, 1.27.0-rc.2) (https://go.dev/cl/775960)
[Unknown] GO-2026-5932: golang.org/x/crypto@v0.53.0 (https://go.dev/issue/44226)

License Violations

All 59 license policy violations (package@version and license)

alpine-baselayout-data@3.7.2-r1 (GPL-2.0-only)
alpine-baselayout@3.7.2-r1 (GPL-2.0-only)
apk-tools@3.0.6-r0 (GPL-2.0-only)
bash@5.3.9-r1 (GPL-3.0-or-later)
busybox-binsh@1.37.0-r31 (GPL-2.0-only)
busybox@1.37.0-r31 (GPL-2.0-only)
ca-certificates-bundle@20260611-r0 (MPL-2.0)
ca-certificates@20260611-r0 (MPL-2.0)
catatonit@0.2.1-r0 (GPL-2.0-or-later)
crun@1.28-r0 (GPL-2.0-or-later, LGPL-2.1-or-later)
fuse-common@3.18.2-r0 (GPL-2.0-only, LGPL-2.1-only)
fuse-overlayfs@1.16-r0 (GPL-2.0-or-later)
fuse3-libs@3.18.2-r0 (GPL-2.0-only, LGPL-2.1-only)
fuse3@3.18.2-r0 (GPL-2.0-only, LGPL-2.1-only)
gdbm@1.26-r0 (GPL-3.0-or-later)
glib@2.88.1-r1 (LGPL-2.1-or-later)
gmp@6.3.0-r4 (GPL-2.0-or-later, LGPL-3.0-or-later)
gnupg-dirmngr@2.4.9-r1 (GPL-3.0-or-later)
gnupg-gpgconf@2.4.9-r1 (GPL-3.0-or-later)
gnupg-keyboxd@2.4.9-r1 (GPL-3.0-or-later)
gnutls@3.8.13-r0 (LGPL-2.1-or-later)
gpg-agent@2.4.9-r1 (GPL-3.0-or-later)
gpg@2.4.9-r1 (GPL-3.0-or-later)
gpgme@2.0.1-r1 (LGPL-2.1-or-later, GPL-3.0-or-later)
gpgsm@2.4.9-r1 (GPL-3.0-or-later)
libapk@3.0.6-r0 (GPL-2.0-only)
libassuan@3.0.2-r0 (LGPL-2.1-or-later)
libblkid@2.42.1-r0 (LGPL-2.1-or-later)
libbz2@1.0.8-r6 (bzip2-1.0.6)
libcap2@2.78-r0 (GPL-2.0-only)
libgcc@15.2.0-r5 (LGPL-2.1-or-later, GPL-2.0-or-later)
libgcrypt@1.12.2-r0 (LGPL-2.1-or-later, GPL-2.0-or-later)
libgpg-error@1.61-r0 (GPL-2.0-or-later, LGPL-2.1-or-later)
libidn2@2.3.8-r0 (GPL-2.0-or-later, LGPL-3.0-or-later)
libintl@1.0-r0 (LGPL-2.1-or-later)
libksba@1.7.0-r0 (LGPL-3.0-only, GPL-2.0-only, GPL-3.0-only)
libldap@2.6.13-r0 (OLDAP-2.8)
libmd@1.2.0-r0 (AND, Beerware, Domain, Public)
libmnl@1.0.5-r2 (LGPL-2.1-or-later)
libmount@2.42.1-r0 (LGPL-2.1-or-later)
libncursesw@6.6_p20260516-r0 (X11)
libnftnl@1.3.1-r0 (GPL-2.0-or-later)
libsasl@2.1.28-r9 (BSD-3-Clause-Attribution, BSD-4-Clause)
libseccomp@2.6.0-r2 (LGPL-2.1-or-later)
libtasn1@4.21.0-r0 (LGPL-2.1-or-later)
libunistring@1.4.2-r0 (GPL-2.0-or-later, LGPL-3.0-or-later)
musl-utils@1.2.6-r2 (GPL-2.0-or-later)
ncurses-terminfo-base@6.6_p20260516-r0 (X11)
nettle@3.10.2-r0 (GPL-2.0-or-later, LGPL-3.0-or-later)
nftables@1.1.6-r1 (GPL-2.0-or-later)
npth@1.8-r0 (LGPL-2.0-or-later)
passt@2026.05.26-r0 (GPL-2.0-or-later)
pinentry@1.3.2-r0 (GPL-2.0-or-later)
readline@8.3.3-r1 (GPL-3.0-or-later)
scanelf@1.3.9-r1 (GPL-2.0-only)
sqlite-libs@3.53.2-r0 (blessing)
ssl_client@1.37.0-r31 (GPL-2.0-only)
zlib@1.3.2-r0 (Zlib)
zstd-libs@1.5.7-r2 (GPL-2.0-or-later)

Remediation

Upgrade go.dev stdlib toolchain used to build fulcio/grpc/x-text/opencontainers dependencies: bump github.com/sigstore/fulcio to 1.8.6+, google.golang.org/grpc to 1.82.1+, golang.org/x/text to 0.39.0+, github.com/opencontainers/runc to 1.4.3+, and Go stdlib to 1.26.5+ to resolve the High/Medium Go vulnerabilities. Rebuild the Alpine base to pick up patched busybox and gnupg packages (CVE-2022-3219 is long-fixed upstream). Review golang.org/x/crypto Unknown-severity finding (GO-2026-5932) for applicability. License violations are mostly copyleft (GPL/LGPL) system packages (gnupg, fuse3, crun, nftables, etc.) from the Alpine base; review/allow-list in Grant policy if acceptable.

Generated by 🛡️ Daily Container Image Security Scan · auto · 581.6 AIC · ⌖ 9.14 AIC · ⊞ 6.5K · ◷

Comments on the Issue (you are @copilot in this section)

Copilot AI linked an issue Aug 11, 2026 that may be closed by this pull request
@pelikhan pelikhan closed this Aug 11, 2026
Copilot stopped work on behalf of pelikhan due to an error August 11, 2026 13:04
Copilot AI requested a review from pelikhan August 11, 2026 13:04
@github-actions
github-actions Bot deleted the copilot/container-image-scan-gh-aw-mcpg branch August 19, 2026 02:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[container-image-scan] Container findings for gh-aw-mcpg

2 participants