Skip to content

[container-image-scan] Container findings for ghcr.io/github/gh-aw-mcpg:v0.4.7 #49508

Description

@github-actions

Summary

Image: ghcr.io/github/gh-aw-mcpg:v0.4.7
Pinned reference: ghcr.io/github/gh-aw-mcpg:v0.4.7@sha256:7545220a9aca134b71e51193ee0eaf4c50756ebf8fbd25a63ae7556e62815c00

  • Vulnerabilities: 19 total — Critical: 0, High: 4, Medium: 8, Low: 6, Negligible: 0, Unknown: 1
  • License policy violations: 59

Remediation

  • Rebuild/update the image to pull in patched packages for the vulnerabilities listed below (fixed versions shown where available).
  • Review the licenses listed below against policy; consider replacing, removing, or granting an exception for flagged packages.
  • Re-run the scan after remediation to confirm the findings are resolved.

Critical & High severity vulnerabilities

[High] GHSA-f5mr-q85p-6hh6: github.com/sigstore/fulcio@v1.8.5 (fix: 1.8.6) (https://github.com/advisories/GHSA-f5mr-q85p-6hh6)
[High] GHSA-hrxh-6v49-42gf: google.golang.org/grpc@v1.81.1 (fix: 1.82.1) (https://github.com/advisories/GHSA-hrxh-6v49-42gf)
[High] GO-2026-4970: stdlib@go1.26.4 (fix: 1.25.12, 1.26.5, 1.27.0-rc.2) (https://go.dev/issue/79005)
[High] GO-2026-5037: stdlib@go1.26.3 (fix: 1.25.11, 1.26.4) (https://go.dev/cl/783621)
Medium / Low / Negligible / Unknown vulnerabilities (15 findings, 14 unique)
[Low] CVE-2022-3219: gnupg-dirmngr@2.4.9-r1 ((nvd.nist.gov/redacted)
[Low] CVE-2022-3219: gnupg-gpgconf@2.4.9-r1 ((nvd.nist.gov/redacted)
[Low] CVE-2022-3219: gnupg-keyboxd@2.4.9-r1 ((nvd.nist.gov/redacted)
[Low] CVE-2022-3219: gpg-agent@2.4.9-r1 ((nvd.nist.gov/redacted)
[Low] CVE-2022-3219: gpg@2.4.9-r1 ((nvd.nist.gov/redacted)
[Low] CVE-2022-3219: gpgsm@2.4.9-r1 ((nvd.nist.gov/redacted)
[Medium] CVE-2025-60876: busybox-binsh@1.37.0-r31 ((nvd.nist.gov/redacted)
[Medium] CVE-2025-60876: busybox@1.37.0-r31 ((nvd.nist.gov/redacted)
[Medium] CVE-2025-60876: ssl_client@1.37.0-r31 ((nvd.nist.gov/redacted)
[Medium] GHSA-xjvp-4fhw-gc47: github.com/opencontainers/runc@v1.4.2 (fix: 1.4.3) (https://github.com/advisories/GHSA-xjvp-4fhw-gc47)
[Medium] GO-2026-5039: stdlib@go1.26.3 (fix: 1.25.11, 1.26.4) (https://go.dev/issue/79346)
[Medium] GO-2026-5856: stdlib@go1.26.3 (fix: 1.25.12, 1.26.5, 1.27.0-rc.2) (https://go.dev/cl/775960)
[Medium] GO-2026-5856: stdlib@go1.26.4 (fix: 1.25.12, 1.26.5, 1.27.0-rc.2) (https://go.dev/cl/775960)
[Unknown] GO-2026-5932: golang.org/x/crypto@v0.53.0 (https://go.dev/issue/44226)
License policy violations (59 findings, 59 unique)
alpine-baselayout-data@3.7.2-r1 (GPL-2.0-only)
alpine-baselayout@3.7.2-r1 (GPL-2.0-only)
apk-tools@3.0.6-r0 (GPL-2.0-only)
bash@5.3.9-r1 (GPL-3.0-or-later)
busybox-binsh@1.37.0-r31 (GPL-2.0-only)
busybox@1.37.0-r31 (GPL-2.0-only)
ca-certificates-bundle@20260611-r0 (MPL-2.0)
ca-certificates@20260611-r0 (MPL-2.0)
catatonit@0.2.1-r0 (GPL-2.0-or-later)
crun@1.28-r0 (GPL-2.0-or-later, LGPL-2.1-or-later)
fuse-common@3.18.2-r0 (GPL-2.0-only, LGPL-2.1-only)
fuse-overlayfs@1.16-r0 (GPL-2.0-or-later)
fuse3-libs@3.18.2-r0 (GPL-2.0-only, LGPL-2.1-only)
fuse3@3.18.2-r0 (GPL-2.0-only, LGPL-2.1-only)
gdbm@1.26-r0 (GPL-3.0-or-later)
glib@2.88.1-r1 (LGPL-2.1-or-later)
gmp@6.3.0-r4 (LGPL-3.0-or-later, GPL-2.0-or-later)
gnupg-dirmngr@2.4.9-r1 (GPL-3.0-or-later)
gnupg-gpgconf@2.4.9-r1 (GPL-3.0-or-later)
gnupg-keyboxd@2.4.9-r1 (GPL-3.0-or-later)
gnutls@3.8.13-r0 (LGPL-2.1-or-later)
gpg-agent@2.4.9-r1 (GPL-3.0-or-later)
gpg@2.4.9-r1 (GPL-3.0-or-later)
gpgme@2.0.1-r1 (LGPL-2.1-or-later, GPL-3.0-or-later)
gpgsm@2.4.9-r1 (GPL-3.0-or-later)
libapk@3.0.6-r0 (GPL-2.0-only)
libassuan@3.0.2-r0 (LGPL-2.1-or-later)
libblkid@2.42.1-r0 (LGPL-2.1-or-later)
libbz2@1.0.8-r6 (bzip2-1.0.6)
libcap2@2.78-r0 (GPL-2.0-only)
libgcc@15.2.0-r5 (GPL-2.0-or-later, LGPL-2.1-or-later)
libgcrypt@1.12.2-r0 (GPL-2.0-or-later, LGPL-2.1-or-later)
libgpg-error@1.61-r0 (GPL-2.0-or-later, LGPL-2.1-or-later)
libidn2@2.3.8-r0 (GPL-2.0-or-later, LGPL-3.0-or-later)
libintl@1.0-r0 (LGPL-2.1-or-later)
libksba@1.7.0-r0 (LGPL-3.0-only, GPL-2.0-only, GPL-3.0-only)
libldap@2.6.13-r0 (OLDAP-2.8)
libmd@1.2.0-r0 (AND, Beerware, Domain, Public)
libmnl@1.0.5-r2 (LGPL-2.1-or-later)
libmount@2.42.1-r0 (LGPL-2.1-or-later)
libncursesw@6.6_p20260516-r0 (X11)
libnftnl@1.3.1-r0 (GPL-2.0-or-later)
libsasl@2.1.28-r9 (BSD-3-Clause-Attribution, BSD-4-Clause)
libseccomp@2.6.0-r2 (LGPL-2.1-or-later)
libtasn1@4.21.0-r0 (LGPL-2.1-or-later)
libunistring@1.4.2-r0 (GPL-2.0-or-later, LGPL-3.0-or-later)
musl-utils@1.2.6-r2 (GPL-2.0-or-later)
ncurses-terminfo-base@6.6_p20260516-r0 (X11)
nettle@3.10.2-r0 (GPL-2.0-or-later, LGPL-3.0-or-later)
nftables@1.1.6-r1 (GPL-2.0-or-later)
npth@1.8-r0 (LGPL-2.0-or-later)
passt@2026.05.26-r0 (GPL-2.0-or-later)
pinentry@1.3.2-r0 (GPL-2.0-or-later)
readline@8.3.3-r1 (GPL-3.0-or-later)
scanelf@1.3.9-r1 (GPL-2.0-only)
sqlite-libs@3.53.2-r0 (blessing)
ssl_client@1.37.0-r31 (GPL-2.0-only)
zlib@1.3.2-r0 (Zlib)
zstd-libs@1.5.7-r2 (GPL-2.0-or-later)

Generated by 🛡️ Daily Container Image Security Scan · auto · 285.1 AIC · ⌖ 8.51 AIC · ⊞ 6.3K ·

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions