Skip to content

[WIP] Fix vulnerabilities in container image ghcr.io/github/github-mcp-server:v1.8.0 - #51332

Closed
pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/container-image-scan-findings
Closed

pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/container-image-scan-findings

Conversation

Copilot AI commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

Thanks for asking me to work on this. I will get started on it and keep this PR's description up to date as I form a plan and make progress.


This section details on the original issue you should resolve

<issue_title>[container-image-scan] Container findings for ghcr.io/github/github-mcp-server:v1.8.0</issue_title>
<issue_description>### Summary

Image: ghcr.io/github/github-mcp-server:v1.8.0
Pinned reference: ghcr.io/github/github-mcp-server:v1.8.0@sha256:d5a18c04b92714c309eb46a2305087e91a4dbd80420f6e462656699f95093520

  • Vulnerabilities: 1 Critical, 3 High, 2 Medium, 8 Negligible
  • License policy violations: 6

Vulnerabilities

1 Critical, 3 High (expand for full list)
  • [Critical] CVE-2026-5450 — libc6@2.36-9+deb12u14 — no fix available yet. (securitytracker.debian.org/redacted)
  • [High] CVE-2026-5928 — libc6@2.36-9+deb12u14 — no fix available yet. (securitytracker.debian.org/redacted)
  • [High] CVE-2026-5435 — libc6@2.36-9+deb12u14 — no fix available yet. (securitytracker.debian.org/redacted)
  • [High] GO-2026-5970 — golang.org/x/text@v0.37.0 — fix: 0.39.0. https://go.dev/issue/80142
2 Medium, 8 Negligible (expand for full list)

Licenses

6 rejected/unknown license findings
  • base-files@12.4+deb12u15 — GPL-2.0-or-later
  • libssl3@3.0.20-1~deb12u2 — Artistic, GPL-1.0-only, GPL-1.0-or-later
  • tzdata@2026b-0+deb12u1 — public-domain
  • libc6@2.36-9+deb12u14 — GPL-2.0-only, HPND, LGPL-2.1-or-later, Spencer-94
  • media-types@10.0.0 — ad-hoc
  • netbase@6.4 — GPL-2.0-only

Remediation

  • Rebuild the github-mcp-server image on top of a patched Debian base (libc6 >= a version fixing CVE-2026-5450/5928/5435) once upstream releases updated packages; track glibc security advisories.
  • Bump the Go module golang.org/x/text to v0.39.0 or later to resolve GO-2026-5970.
  • Review GPL/Artistic-licensed base packages (base-files, libssl3, libc6, netbase) against organizational license policy; these are typically unavoidable in Debian-based images but should be explicitly allow-listed if acceptable.

Generated by 🛡️ Daily Container Image Security Scan · auto · 434.8 AIC · ⌖ 3.45 AIC · ⊞ 6.5K · ◷

Comments on the Issue (you are @copilot in this section)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[container-image-scan] Container findings for ghcr.io/github/github-mcp-server:v1.8.0

2 participants