Skip to content

fix: disable mcp/ast-grep container due to Critical/High CVEs - #49823

Closed
pelikhan with Copilot wants to merge 2 commits into
mainfrom
copilot/container-image-scan-remediation-again
Closed

fix: disable mcp/ast-grep container due to Critical/High CVEs#49823
pelikhan with Copilot wants to merge 2 commits into
mainfrom
copilot/container-image-scan-remediation-again

Conversation

Copilot AI commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

mcp/ast-grep:latest has 6 Critical and 38 High CVEs — primarily in Alpine's libcrypto3/libssl3/musl and stdlib@go1.25.1 — with no upstream-patched image currently available.

Changes

  • shared/mcp/ast-grep.md — Remove mcp-servers block; replace with security comment (consistent with pattern used for brave.md, notion.md, semgrep.md)
  • mcp-inspector.md — Comment out shared/mcp/ast-grep.md import with CVE note
  • go-pattern-detector.md — Comment out shared/mcp/ast-grep.md import with CVE note; standalone cargo install ast-grep detection step is unaffected
  • Lock files — Recompiled; mcp/ast-grep:latest container reference removed from both affected lock files

…49513)

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Update mcp/ast-grep:latest for security vulnerabilities fix: disable mcp/ast-grep container due to Critical/High CVEs Aug 2, 2026
Copilot AI requested a review from pelikhan August 2, 2026 18:24
@pelikhan pelikhan closed this Aug 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[container-image-scan] Container findings for mcp/ast-grep:latest

2 participants