Skip to content

[container-image-scan] Container findings for ca96b8acb27d #47428

Description

@github-actions

Container Scan Report

Scan date: 2026-07-22
Scanners: Syft 1.49.0 · Grype 0.116.0 · Grant 0.6.8
Grype DB: schema v6.1.9, built 2026-07-22T07:06:24Z, status valid

Image

Field Value
Tag docker.io/mcp/brave-search
Pinned digest sha256:ca96b8acb27d8cf601a8faef86a084602cffa41d8cb18caa1e29ba4d16989d22
Current tag digest sha256:f58a5c22c1196ec7bd1ca586ce216f2334fc298550ddcf652c0e8adb6d256d78
Digest drift ⚠️ YES — tag has moved since pinned

Platform child digests:

Platform Digest
linux/amd64 sha256:ae3b30d079370f67495d75085ffb73a11efcf9f9b23b919ffcb990ed2c076cfe
linux/arm64 sha256:146395f4374107e490ff6038b4a0326eaf57252d06f96275132ad56fa0334199

Vulnerability Summary

Total: 256 · Critical: 14 · Fixable: 250

Critical & High vulnerabilities (linux/amd64)

Package Installed Fixed In Type CVE/ID Severity
tar 7.5.9 7.5.19 npm GHSA-23hp-3jrh-7fpw Critical
libcrypto3 3.5.5-r0 3.5.7-r0 apk CVE-2026-34182 Critical
libssl3 3.5.5-r0 3.5.7-r0 apk CVE-2026-34182 Critical
openssl 3.5.5-r0 3.5.7-r0 apk CVE-2026-34182 Critical
libcrypto3 3.5.5-r0 3.5.6-r0 apk CVE-2026-31789 Critical
libssl3 3.5.5-r0 3.5.6-r0 apk CVE-2026-31789 Critical
openssl 3.5.5-r0 3.5.6-r0 apk CVE-2026-31789 Critical
node 25.8.1 20.20.2,22.22.2,24.14.1,*25.8.2 binary CVE-2026-21710 High
libcrypto3 3.5.5-r0 3.5.7-r0 apk CVE-2026-45447 High
libssl3 3.5.5-r0 3.5.7-r0 apk CVE-2026-45447 High
openssl 3.5.5-r0 3.5.7-r0 apk CVE-2026-45447 High
musl 1.2.5-r21 1.2.5-r23 apk CVE-2026-40200 High
musl-utils 1.2.5-r21 1.2.5-r23 apk CVE-2026-40200 High
sigstore 4.1.0 4.1.1 npm GHSA-52v5-jr5w-gjxr High
hono 4.12.12 4.12.25 npm GHSA-88fw-hqm2-52qc High
fast-uri 3.1.0 3.1.1 npm GHSA-q3j6-qgpj-74h6 High
minimatch 10.2.2 10.2.3 npm GHSA-7r86-cg39-jmmj High
picomatch 4.0.3 4.0.4 npm GHSA-c2c7-rcm5-vvqj High
brace-expansion 5.0.3 5.0.7 npm GHSA-3jxr-9vmj-r5cp High

arm64 findings are identical for openssl/libcrypto3/tar/hono/node.

License Violations (Grant)

Policy allows: MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISC
Denied packages (amd64): 27 across 11 denied license types

License Packages Risk
GPL-2.0-only 8 High
GPL-2.0-or-later 3 High
LGPL-2.1-or-later 2 Medium
MPL-2.0 1 Medium
BlueOak-1.0.0 10 Unknown
CC-BY-3.0 1 Unknown
CC0-1.0 1 Unknown
(no licenses found) 1 Unknown

Remediation

  1. Digest drift: Update pinned digest to sha256:f58a5c22c1196ec7bd1ca586ce216f2334fc298550ddcf652c0e8adb6d256d78 after verification.
  2. openssl/libcrypto3/libssl3: Upgrade to Alpine 3.5.7-r0 (fixes CVE-2026-34182 Critical, CVE-2026-45447 High, and multiple others).
  3. node: Upgrade to 25.8.2+ (fixes CVE-2026-21710 High).
  4. tar: Upgrade to 7.5.19 (fixes GHSA-23hp-3jrh-7fpw Critical).
  5. musl/musl-utils: Upgrade to 1.2.5-r23 (fixes CVE-2026-40200 High).
  6. hono: Upgrade to 4.12.27 (fixes multiple High/Medium advisories).
  7. License violations: Review GPL/LGPL/MPL packages for compliance; consider replacing or obtaining commercial licenses.

Generated by 🛡️ Daily Container Image Security Scan · sonnet46 130.3 AIC · ⌖ 8.9 AIC · ⊞ 4.5K ·

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions