Skip to content

[container-image-scan] Container findings for ghcr.io/github/gh-aw-mcpg #48149

Description

@github-actions

Summary

Image: ghcr.io/github/gh-aw-mcpg:v0.4.5@sha256:7550c5132d007266b696d77218e8d1b01f29e6e55520875b2431ef4044df71c9

Grype found 1 Critical and 13 High vulnerabilities. All critical/high findings are in Go stdlib go1.24.12 (outdated) and docker-cli.

Vulnerabilities

Critical severity (1)
CVE / ID Package Installed Fix
[GO-2026-4337]((groups.google.com/redacted) stdlib go1.24.12 1.24.13 / 1.26.0-rc.3
High severity (13)
CVE / ID Package Installed Fix
GO-2026-4981 stdlib go1.24.12 1.26.3
GO-2026-4977 stdlib go1.24.12 1.26.3
GO-2026-4986 stdlib go1.24.12 1.26.3
GO-2026-4918 stdlib go1.24.12 1.26.3
GO-2026-4601 stdlib go1.24.12 1.26.1
GO-2026-4870 stdlib go1.24.12 1.26.2
GO-2026-4947 stdlib go1.24.12 1.26.2
GO-2026-5037 stdlib go1.24.12 1.26.4
GO-2026-4971 stdlib go1.24.12 1.26.3
GO-2026-5038 stdlib go1.24.12 1.26.4
GO-2026-4946 stdlib go1.24.12 1.26.2
GO-2026-4970 stdlib go1.24.12 1.26.5
[CVE-2026-42306]((nvd.nist.gov/redacted) docker-cli 28.3.3-r5

Remediation

  • Rebuild with Go ≥1.26.5 to resolve all Go stdlib vulnerabilities.
  • Update docker-cli when a patched Alpine package is available.

Generated by 🛡️ Daily Container Image Security Scan · sonnet46 · 161.6 AIC · ⌖ 6.65 AIC · ⊞ 4.5K ·

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions