Container Scan Report
Scan date: 2026-07-22
Scanners: Syft 1.49.0 · Grype 0.116.0 · Grant 0.6.8
Grype DB: schema v6.1.9, built 2026-07-22T07:06:24Z, status valid
Image
| Field |
Value |
| Tag |
docker.io/mcp/brave-search |
| Pinned digest |
sha256:ca96b8acb27d8cf601a8faef86a084602cffa41d8cb18caa1e29ba4d16989d22 |
| Current tag digest |
sha256:f58a5c22c1196ec7bd1ca586ce216f2334fc298550ddcf652c0e8adb6d256d78 |
| Digest drift |
⚠️ YES — tag has moved since pinned |
Platform child digests:
| Platform |
Digest |
| linux/amd64 |
sha256:ae3b30d079370f67495d75085ffb73a11efcf9f9b23b919ffcb990ed2c076cfe |
| linux/arm64 |
sha256:146395f4374107e490ff6038b4a0326eaf57252d06f96275132ad56fa0334199 |
Vulnerability Summary
Total: 256 · Critical: 14 · Fixable: 250
Critical & High vulnerabilities (linux/amd64)
arm64 findings are identical for openssl/libcrypto3/tar/hono/node.
License Violations (Grant)
Policy allows: MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISC
Denied packages (amd64): 27 across 11 denied license types
| License |
Packages |
Risk |
| GPL-2.0-only |
8 |
High |
| GPL-2.0-or-later |
3 |
High |
| LGPL-2.1-or-later |
2 |
Medium |
| MPL-2.0 |
1 |
Medium |
| BlueOak-1.0.0 |
10 |
Unknown |
| CC-BY-3.0 |
1 |
Unknown |
| CC0-1.0 |
1 |
Unknown |
| (no licenses found) |
1 |
Unknown |
Remediation
- Digest drift: Update pinned digest to
sha256:f58a5c22c1196ec7bd1ca586ce216f2334fc298550ddcf652c0e8adb6d256d78 after verification.
- openssl/libcrypto3/libssl3: Upgrade to Alpine 3.5.7-r0 (fixes CVE-2026-34182 Critical, CVE-2026-45447 High, and multiple others).
- node: Upgrade to 25.8.2+ (fixes CVE-2026-21710 High).
- tar: Upgrade to 7.5.19 (fixes GHSA-23hp-3jrh-7fpw Critical).
- musl/musl-utils: Upgrade to 1.2.5-r23 (fixes CVE-2026-40200 High).
- hono: Upgrade to 4.12.27 (fixes multiple High/Medium advisories).
- License violations: Review GPL/LGPL/MPL packages for compliance; consider replacing or obtaining commercial licenses.
Generated by 🛡️ Daily Container Image Security Scan · sonnet46 130.3 AIC · ⌖ 8.9 AIC · ⊞ 4.5K · ◷
Container Scan Report
Scan date: 2026-07-22
Scanners: Syft 1.49.0 · Grype 0.116.0 · Grant 0.6.8
Grype DB: schema v6.1.9, built 2026-07-22T07:06:24Z, status valid
Image
docker.io/mcp/brave-searchsha256:ca96b8acb27d8cf601a8faef86a084602cffa41d8cb18caa1e29ba4d16989d22sha256:f58a5c22c1196ec7bd1ca586ce216f2334fc298550ddcf652c0e8adb6d256d78Platform child digests:
sha256:ae3b30d079370f67495d75085ffb73a11efcf9f9b23b919ffcb990ed2c076cfesha256:146395f4374107e490ff6038b4a0326eaf57252d06f96275132ad56fa0334199Vulnerability Summary
Total: 256 · Critical: 14 · Fixable: 250
Critical & High vulnerabilities (linux/amd64)
arm64 findings are identical for openssl/libcrypto3/tar/hono/node.
License Violations (Grant)
Policy allows: MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISC
Denied packages (amd64): 27 across 11 denied license types
Remediation
sha256:f58a5c22c1196ec7bd1ca586ce216f2334fc298550ddcf652c0e8adb6d256d78after verification.