Skip to content

[container-image-scan] Container findings for docker.io/mcp/brave-search #48546

Description

@github-actions

Summary

  • Image: docker.io/mcp/brave-search
  • Pinned reference: docker.io/mcp/brave-search@sha256:f58a5c22c1196ec7bd1ca586ce216f2334fc298550ddcf652c0e8adb6d256d78
  • Vulnerabilities: 15 (Critical: 1, High: 14)
  • License policy violations: 28

Vulnerabilities

Click to expand 15 vulnerability findings
Severity CVE/GHSA Package Installed Fixed
Critical GHSA-23hp-3jrh-7fpw tar 7.5.9 7.5.19
High CVE-2026-21710 node 25.8.1 20.20.2, 22.22.2, 24.14.1, 25.8.2
High CVE-2026-40200 musl-utils 1.2.5-r21 1.2.5-r23
High CVE-2026-40200 musl 1.2.5-r21 1.2.5-r23
High GHSA-23c5-xmqv-rm74 minimatch 10.2.2 10.2.3
High GHSA-3jxr-9vmj-r5cp brace-expansion 5.0.3 5.0.7
High GHSA-4c8g-83qw-93j6 fast-uri 3.1.2 3.1.3
High GHSA-52v5-jr5w-gjxr sigstore 4.1.0 4.1.1
High GHSA-7r86-cg39-jmmj minimatch 10.2.2 10.2.3
High GHSA-8x88-c5mf-7j5w tar 7.5.9 7.5.18
High GHSA-9ppj-qmqm-q256 tar 7.5.9 7.5.11
High GHSA-c2c7-rcm5-vvqj picomatch 4.0.3 4.0.4
High GHSA-mh99-v99m-4gvg brace-expansion 5.0.3 5.0.8
High GHSA-qffp-2rhf-9h96 tar 7.5.9 7.5.10
High GHSA-v2hh-gcrm-f6hx fast-uri 3.1.2 3.1.4

License Policy Violations

Click to expand 28 license findings
Package Licenses
alpine-baselayout-data@3.7.1-r8 GPL-2.0-only
alpine-baselayout@3.7.1-r8 GPL-2.0-only
apk-tools@3.0.3-r1 GPL-2.0-only
busybox-binsh@1.37.0-r30 GPL-2.0-only
busybox@1.37.0-r30 GPL-2.0-only
ca-certificates-bundle@20251003-r0 MPL-2.0
chownr@3.0.0 BlueOak-1.0.0
common-ancestor-path@2.0.0 BlueOak-1.0.0
glob@13.0.6 BlueOak-1.0.0
isexe@4.0.0 BlueOak-1.0.0
libapk@3.0.3-r1 GPL-2.0-only
libgcc@15.2.0-r2 GPL-2.0-or-later, LGPL-2.1-or-later
libstdc++@15.2.0-r2 GPL-2.0-or-later, LGPL-2.1-or-later
lru-cache@11.2.6 BlueOak-1.0.0
minimatch@10.2.2 BlueOak-1.0.0
minipass@7.1.3 BlueOak-1.0.0
musl-utils@1.2.5-r21 GPL-2.0-or-later
node@25.8.1 no licenses found
npm@11.11.0 Artistic-2.0
path-scurry@2.0.2 BlueOak-1.0.0
qrcode-terminal@0.12.0 Apache 2.0
scanelf@1.3.8-r2 GPL-2.0-only
spdx-exceptions@2.5.0 CC-BY-3.0
spdx-license-ids@3.0.23 CC0-1.0
ssl_client@1.37.0-r30 GPL-2.0-only
tar@7.5.9 BlueOak-1.0.0
yallist@5.0.0 BlueOak-1.0.0
zlib@1.3.1-r2 Zlib

Remediation

  • Upgrade vulnerable packages to the fixed versions listed above where available; rebuild and re-pin the image digest.
  • For findings with no fixed version, monitor upstream advisories and track for a future patch release.
  • For license policy violations, review whether the flagged component is required; replace with a policy-compliant alternative, or add an explicit exception if the license is acceptable for this use case.

Generated by 🛡️ Daily Container Image Security Scan · sonnet50 · 331.8 AIC · ⌖ 8.81 AIC · ⊞ 5.9K ·

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions