Skip to content

[container-image-scan] Container findings for ghcr.io/github/gh-aw-mcpg #52456

Description

@github-actions

Summary

Image: ghcr.io/github/gh-aw-mcpg:v0.4.9@sha256:2f4d9a71c0...

4 High, 6 Medium, 6 Low, 1 Unknown-severity vulnerabilities; 59 license policy violations.

Remediation

  • Upgrade Go toolchain/stdlib to >= 1.25.11/1.26.4 (GO-2026-5037, GO-2026-5039) and >= 1.25.12/1.26.5/1.27.0-rc.2 (GO-2026-5856, GO-2026-4970).
  • Update golang.org/x/text to >= 0.39.0 (GO-2026-5970), github.com/sigstore/fulcio to >= 1.8.6, google.golang.org/grpc to >= 1.82.1, github.com/opencontainers/runc to >= 1.4.3.
  • Review golang.org/x/crypto@v0.53.0 for GO-2026-5932 (no fixed version published yet — track upstream).
  • gnupg-*/gpg* packages report CVE-2022-3219 (Low, denial-of-service via crafted OpenPGP packet) — no fix available in this Alpine release; low risk if GnuPG is not exposed to untrusted input.
  • Update Alpine busybox/ssl_client once patched packages ship for CVE-2025-60876.
  • License violations are dominated by Alpine base-layer GPL-2.0/LGPL packages (needed for container tooling: crun, fuse-overlayfs, nftables, catatonit, gnupg suite) — treat as accepted policy exception for base-OS/container-runtime packages.

Vulnerabilities

17 vulnerabilities across Go modules, Alpine packages, and container tooling
Severity ID Package Installed Fixed
High GO-2026-5037 stdlib go1.26.3 1.25.11, 1.26.4
High GO-2026-5970 golang.org/x/text v0.38.0 0.39.0
High GO-2026-4970 stdlib go1.26.4 1.25.12, 1.26.5, 1.27.0-rc.2
High GHSA-f5mr-q85p-6hh6 github.com/sigstore/fulcio v1.8.5 1.8.6
High GHSA-hrxh-6v49-42gf google.golang.org/grpc v1.81.1 1.82.1
Medium GO-2026-5856 stdlib go1.26.3 / go1.26.4 1.25.12, 1.26.5, 1.27.0-rc.2
Medium GO-2026-5039 stdlib go1.26.3 1.25.11, 1.26.4
Medium CVE-2025-60876 busybox 1.37.0-r31 not specified
Medium CVE-2025-60876 busybox-binsh 1.37.0-r31 not specified
Medium CVE-2025-60876 ssl_client 1.37.0-r31 not specified
Medium GHSA-xjvp-4fhw-gc47 github.com/opencontainers/runc v1.4.2 1.4.3
Low CVE-2022-3219 gnupg-dirmngr 2.4.9-r1 none available
Low CVE-2022-3219 gnupg-gpgconf 2.4.9-r1 none available
Low CVE-2022-3219 gnupg-keyboxd 2.4.9-r1 none available
Low CVE-2022-3219 gpg 2.4.9-r1 none available
Low CVE-2022-3219 gpg-agent 2.4.9-r1 none available
Low CVE-2022-3219 gpgsm 2.4.9-r1 none available
Unknown GO-2026-5932 golang.org/x/crypto v0.53.0 none available

License Violations

59 rejected/unknown licenses (mostly container-tooling and GnuPG dependencies)
Package Version License(s)
libintl 1.0-r0 LGPL-2.1-or-later
libmd 1.2.0-r0 AND, Beerware, Domain, Public
nftables 1.1.6-r1 GPL-2.0-or-later
busybox 1.37.0-r31 GPL-2.0-only
libapk 3.0.6-r0 GPL-2.0-only
libtasn1 4.21.0-r0 LGPL-2.1-or-later
ca-certificates-bundle 20260611-r0 MPL-2.0
readline 8.3.3-r1 GPL-3.0-or-later
libcap2 2.78-r0 GPL-2.0-only
busybox-binsh 1.37.0-r31 GPL-2.0-only
sqlite-libs 3.53.2-r0 blessing
bash 5.3.9-r1 GPL-3.0-or-later
gpg 2.4.9-r1 GPL-3.0-or-later
fuse3-libs 3.18.2-r0 GPL-2.0-only, LGPL-2.1-only
libidn2 2.3.8-r0 GPL-2.0-or-later, LGPL-3.0-or-later
ncurses-terminfo-base 6.6_p20260516-r0 X11
apk-tools 3.0.6-r0 GPL-2.0-only
libmnl 1.0.5-r2 LGPL-2.1-or-later
fuse-common 3.18.2-r0 GPL-2.0-only, LGPL-2.1-only
gnupg-dirmngr 2.4.9-r1 GPL-3.0-or-later
passt 2026.05.26-r0 GPL-2.0-or-later
libbz2 1.0.8-r6 bzip2-1.0.6
gpgsm 2.4.9-r1 GPL-3.0-or-later
libsasl 2.1.28-r9 BSD-4-Clause, BSD-3-Clause-Attribution
gmp 6.3.0-r4 LGPL-3.0-or-later, GPL-2.0-or-later
nettle 3.10.2-r0 GPL-2.0-or-later, LGPL-3.0-or-later
musl-utils 1.2.6-r2 GPL-2.0-or-later
zstd-libs 1.5.7-r2 GPL-2.0-or-later
zlib 1.3.2-r0 Zlib
ssl_client 1.37.0-r31 GPL-2.0-only
scanelf 1.3.9-r1 GPL-2.0-only
fuse3 3.18.2-r0 GPL-2.0-only, LGPL-2.1-only
gpg-agent 2.4.9-r1 GPL-3.0-or-later
gpgme 2.0.1-r1 LGPL-2.1-or-later, GPL-3.0-or-later
alpine-baselayout 3.7.2-r1 GPL-2.0-only
ca-certificates 20260611-r0 MPL-2.0
gdbm 1.26-r0 GPL-3.0-or-later
libgcc 15.2.0-r5 LGPL-2.1-or-later, GPL-2.0-or-later
npth 1.8-r0 LGPL-2.0-or-later
libassuan 3.0.2-r0 LGPL-2.1-or-later
libldap 2.6.13-r0 OLDAP-2.8
libblkid 2.42.1-r0 LGPL-2.1-or-later
libncursesw 6.6_p20260516-r0 X11
crun 1.28-r0 LGPL-2.1-or-later, GPL-2.0-or-later
gnupg-gpgconf 2.4.9-r1 GPL-3.0-or-later
alpine-baselayout-data 3.7.2-r1 GPL-2.0-only
libseccomp 2.6.0-r2 LGPL-2.1-or-later
pinentry 1.3.2-r0 GPL-2.0-or-later
libunistring 1.4.2-r0 GPL-2.0-or-later, LGPL-3.0-or-later
catatonit 0.2.1-r0 GPL-2.0-or-later
fuse-overlayfs 1.16-r0 GPL-2.0-or-later
libnftnl 1.3.1-r0 GPL-2.0-or-later
libmount 2.42.1-r0 LGPL-2.1-or-later
libksba 1.7.0-r0 LGPL-3.0-only, GPL-2.0-only, GPL-3.0-only
gnupg-keyboxd 2.4.9-r1 GPL-3.0-or-later
libgcrypt 1.12.2-r0 LGPL-2.1-or-later, GPL-2.0-or-later
libgpg-error 1.61-r0 GPL-2.0-or-later, LGPL-2.1-or-later
glib 2.88.1-r1 LGPL-2.1-or-later
gnutls 3.8.13-r0 LGPL-2.1-or-later

Generated by 🛡️ Daily Container Image Security Scan · auto · 327.5 AIC · ⌖ 10.6 AIC · ⊞ 6.5K ·

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions