GO-2026-6599: stdlib@go1.27.1 (fix: 1.26.9, 1.27.2)
GO-2026-6600: stdlib@go1.27.1 (fix: 1.26.9, 1.27.2)
GO-2026-6603: stdlib@go1.27.1 (fix: 1.27.2)
GO-2026-6605: stdlib@go1.27.1 (fix: 1.26.9, 1.27.2)
GO-2026-6607: stdlib@go1.27.1 (fix: 1.26.9, 1.27.2)
GO-2026-6608: stdlib@go1.27.1 (fix: 1.26.9, 1.27.2)
GO-2026-6610: stdlib@go1.27.1 (fix: 1.27.2)
GO-2026-6611: stdlib@go1.27.1 (fix: 1.27.2)
GO-2026-6612: stdlib@go1.27.1 (fix: 1.27.2)
GO-2026-6613: stdlib@go1.27.1 (fix: 1.26.9, 1.27.2)
GO-2026-6617: stdlib@go1.27.1 (fix: 1.27.2)
GitHub MCP Server scan summary
Status: Upstream (owned by
github/github-mcp-server). Unique finding rows: 1 Critical, 5 High, 14 Medium, 5 Low, 11 Unknown; 0 license violations.Images
ghcr.io/github/github-mcp-server:v1.12.2@sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6Findings by severity
Critical
High
Medium
Low
Unknown
Remediation and SLA
gh aw compile --force-refresh-container-pins, so a pin-refresh PR is the default remediation step.github/gh-aw; a code-level fix cannot land here. Do not request a local patch PR. The daily pin refresh picks up upstream fixes once released.pkg@installed => fixedlist the fixed package version reported by Grype. The image release/digest containing each fix has not been confirmed from this scan; rows with no fix listed have no fixed package version reported.ID pkg@versionentries from the scan.