Skip to content

[container-image-scan] Container findings for ca96b8acb27d #47428

Description

@github-actions

Container Scan Report

Scan date: 2026-07-22
Scanners: Syft 1.49.0 · Grype 0.116.0 · Grant 0.6.8
Grype DB: schema v6.1.9, built 2026-07-22T07:06:24Z, status valid

Image

Field Value
Tag docker.io/mcp/brave-search
Pinned digest sha256:ca96b8acb27d8cf601a8faef86a084602cffa41d8cb18caa1e29ba4d16989d22
Current tag digest sha256:f58a5c22c1196ec7bd1ca586ce216f2334fc298550ddcf652c0e8adb6d256d78
Digest drift ⚠️ YES — tag has moved since pinned

Platform child digests:

Platform Digest
linux/amd64 sha256:ae3b30d079370f67495d75085ffb73a11efcf9f9b23b919ffcb990ed2c076cfe
linux/arm64 sha256:146395f4374107e490ff6038b4a0326eaf57252d06f96275132ad56fa0334199

Vulnerability Summary

Total: 256 · Critical: 14 · Fixable: 250

Critical & High vulnerabilities (linux/amd64)

Package Installed Fixed In Type CVE/ID Severity
tar 7.5.9 7.5.19 npm GHSA-23hp-3jrh-7fpw Critical
libcrypto3 3.5.5-r0 3.5.7-r0 apk CVE-2026-34182 Critical
libssl3 3.5.5-r0 3.5.7-r0 apk CVE-2026-34182 Critical
openssl 3.5.5-r0 3.5.7-r0 apk CVE-2026-34182 Critical
libcrypto3 3.5.5-r0 3.5.6-r0 apk CVE-2026-31789 Critical
libssl3 3.5.5-r0 3.5.6-r0 apk CVE-2026-31789 Critical
openssl 3.5.5-r0 3.5.6-r0 apk CVE-2026-31789 Critical
node 25.8.1 20.20.2,22.22.2,24.14.1,*25.8.2 binary CVE-2026-21710 High
libcrypto3 3.5.5-r0 3.5.7-r0 apk CVE-2026-45447 High
libssl3 3.5.5-r0 3.5.7-r0 apk CVE-2026-45447 High
openssl 3.5.5-r0 3.5.7-r0 apk CVE-2026-45447 High
musl 1.2.5-r21 1.2.5-r23 apk CVE-2026-40200 High
musl-utils 1.2.5-r21 1.2.5-r23 apk CVE-2026-40200 High
sigstore 4.1.0 4.1.1 npm GHSA-52v5-jr5w-gjxr High
hono 4.12.12 4.12.25 npm GHSA-88fw-hqm2-52qc High
fast-uri 3.1.0 3.1.1 npm GHSA-q3j6-qgpj-74h6 High
minimatch 10.2.2 10.2.3 npm GHSA-7r86-cg39-jmmj High
picomatch 4.0.3 4.0.4 npm GHSA-c2c7-rcm5-vvqj High
brace-expansion 5.0.3 5.0.7 npm GHSA-3jxr-9vmj-r5cp High

arm64 findings are identical for openssl/libcrypto3/tar/hono/node.

License Violations (Grant)

Policy allows: MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISC
Denied packages (amd64): 27 across 11 denied license types

License Packages Risk
GPL-2.0-only 8 High
GPL-2.0-or-later 3 High
LGPL-2.1-or-later 2 Medium
MPL-2.0 1 Medium
BlueOak-1.0.0 10 Unknown
CC-BY-3.0 1 Unknown
CC0-1.0 1 Unknown
(no licenses found) 1 Unknown

Remediation

  1. Digest drift: Update pinned digest to sha256:f58a5c22c1196ec7bd1ca586ce216f2334fc298550ddcf652c0e8adb6d256d78 after verification.
  2. openssl/libcrypto3/libssl3: Upgrade to Alpine 3.5.7-r0 (fixes CVE-2026-34182 Critical, CVE-2026-45447 High, and multiple others).
  3. node: Upgrade to 25.8.2+ (fixes CVE-2026-21710 High).
  4. tar: Upgrade to 7.5.19 (fixes GHSA-23hp-3jrh-7fpw Critical).
  5. musl/musl-utils: Upgrade to 1.2.5-r23 (fixes CVE-2026-40200 High).
  6. hono: Upgrade to 4.12.27 (fixes multiple High/Medium advisories).
  7. License violations: Review GPL/LGPL/MPL packages for compliance; consider replacing or obtaining commercial licenses.

Generated by 🛡️ Daily Container Image Security Scan · sonnet46 130.3 AIC · ⌖ 8.9 AIC · ⊞ 4.5K ·

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions