Skip to content

[WIP] Fix vulnerabilities in container image ghcr.io/github/github-mcp-server:v1.8.0 - #49810

Closed
pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/container-image-scan-fix-vulnerabilities-one-more-time
Closed

[WIP] Fix vulnerabilities in container image ghcr.io/github/github-mcp-server:v1.8.0#49810
pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/container-image-scan-fix-vulnerabilities-one-more-time

Conversation

Copilot AI commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Thanks for asking me to work on this. I will get started on it and keep this PR's description up to date as I form a plan and make progress.


This section details on the original issue you should resolve

<issue_title>[container-image-scan] Container findings for ghcr.io/github/github-mcp-server:v1.8.0</issue_title>
<issue_description>### Summary

Image: ghcr.io/github/github-mcp-server:v1.8.0
Pinned reference: ghcr.io/github/github-mcp-server:v1.8.0@sha256:d5a18c04b92714c309eb46a2305087e91a4dbd80420f6e462656699f95093520

  • Vulnerabilities: 13 total — Critical: 1, High: 2, Medium: 2, Low: 0, Negligible: 8, Unknown: 0
  • License policy violations: 6

Remediation

  • Rebuild/update the image to pull in patched packages for the vulnerabilities listed below (fixed versions shown where available).
  • Review the licenses listed below against policy; consider replacing, removing, or granting an exception for flagged packages.
  • Re-run the scan after remediation to confirm the findings are resolved.

Critical & High severity vulnerabilities

[Critical] CVE-2026-5450: libc6@2.36-9+deb12u14 ((securitytracker.debian.org/redacted)
[High] CVE-2026-5435: libc6@2.36-9+deb12u14 ((securitytracker.debian.org/redacted)
[High] CVE-2026-5928: libc6@2.36-9+deb12u14 ((securitytracker.debian.org/redacted)
Medium / Low / Negligible / Unknown vulnerabilities (10 findings, 10 unique)
[Medium] CVE-2026-42767: libssl3@3.0.20-1~deb12u2 ((securitytracker.debian.org/redacted)
[Medium] CVE-2026-6238: libc6@2.36-9+deb12u14 ((securitytracker.debian.org/redacted)
[Negligible] CVE-2010-4756: libc6@2.36-9+deb12u14 ((securitytracker.debian.org/redacted)
[Negligible] CVE-2018-20796: libc6@2.36-9+deb12u14 ((securitytracker.debian.org/redacted)
[Negligible] CVE-2019-1010022: libc6@2.36-9+deb12u14 ((securitytracker.debian.org/redacted)
[Negligible] CVE-2019-1010023: libc6@2.36-9+deb12u14 ((securitytracker.debian.org/redacted)
[Negligible] CVE-2019-1010024: libc6@2.36-9+deb12u14 ((securitytracker.debian.org/redacted)
[Negligible] CVE-2019-1010025: libc6@2.36-9+deb12u14 ((securitytracker.debian.org/redacted)
[Negligible] CVE-2019-9192: libc6@2.36-9+deb12u14 ((securitytracker.debian.org/redacted)
[Negligible] CVE-2025-27587: libssl3@3.0.20-1~deb12u2 ((securitytracker.debian.org/redacted)
License policy violations (6 findings, 6 unique)
base-files@12.4+deb12u15 (GPL-2.0-or-later)
libc6@2.36-9+deb12u14 (GPL-2.0-only, HPND, LGPL-2.1-or-later, Spencer-94)
libssl3@3.0.20-1~deb12u2 (Artistic, GPL-1.0-only, GPL-1.0-or-later)
media-types@10.0.0 (ad-hoc)
netbase@6.4 (GPL-2.0-only)
tzdata@2026b-0+deb12u1 (public-domain)

Generated by 🛡️ Daily Container Image Security Scan · auto · 285.1 AIC · ⌖ 8.51 AIC · ⊞ 6.3K ·

Comments on the Issue (you are @copilot in this section)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[container-image-scan] Container findings for ghcr.io/github/github-mcp-server:v1.8.0

2 participants