Skip to content

[container-image-scan] Container findings for docker.io/mcp/brave-search #48546

Description

@github-actions

Summary

  • Image: docker.io/mcp/brave-search
  • Pinned reference: docker.io/mcp/brave-search@sha256:f58a5c22c1196ec7bd1ca586ce216f2334fc298550ddcf652c0e8adb6d256d78
  • Vulnerabilities: 15 (Critical: 1, High: 14)
  • License policy violations: 28

Vulnerabilities

Click to expand 15 vulnerability findings
Severity CVE/GHSA Package Installed Fixed
Critical GHSA-23hp-3jrh-7fpw tar 7.5.9 7.5.19
High CVE-2026-21710 node 25.8.1 20.20.2, 22.22.2, 24.14.1, 25.8.2
High CVE-2026-40200 musl-utils 1.2.5-r21 1.2.5-r23
High CVE-2026-40200 musl 1.2.5-r21 1.2.5-r23
High GHSA-23c5-xmqv-rm74 minimatch 10.2.2 10.2.3
High GHSA-3jxr-9vmj-r5cp brace-expansion 5.0.3 5.0.7
High GHSA-4c8g-83qw-93j6 fast-uri 3.1.2 3.1.3
High GHSA-52v5-jr5w-gjxr sigstore 4.1.0 4.1.1
High GHSA-7r86-cg39-jmmj minimatch 10.2.2 10.2.3
High GHSA-8x88-c5mf-7j5w tar 7.5.9 7.5.18
High GHSA-9ppj-qmqm-q256 tar 7.5.9 7.5.11
High GHSA-c2c7-rcm5-vvqj picomatch 4.0.3 4.0.4
High GHSA-mh99-v99m-4gvg brace-expansion 5.0.3 5.0.8
High GHSA-qffp-2rhf-9h96 tar 7.5.9 7.5.10
High GHSA-v2hh-gcrm-f6hx fast-uri 3.1.2 3.1.4

License Policy Violations

Click to expand 28 license findings
Package Licenses
alpine-baselayout-data@3.7.1-r8 GPL-2.0-only
alpine-baselayout@3.7.1-r8 GPL-2.0-only
apk-tools@3.0.3-r1 GPL-2.0-only
busybox-binsh@1.37.0-r30 GPL-2.0-only
busybox@1.37.0-r30 GPL-2.0-only
ca-certificates-bundle@20251003-r0 MPL-2.0
chownr@3.0.0 BlueOak-1.0.0
common-ancestor-path@2.0.0 BlueOak-1.0.0
glob@13.0.6 BlueOak-1.0.0
isexe@4.0.0 BlueOak-1.0.0
libapk@3.0.3-r1 GPL-2.0-only
libgcc@15.2.0-r2 GPL-2.0-or-later, LGPL-2.1-or-later
libstdc++@15.2.0-r2 GPL-2.0-or-later, LGPL-2.1-or-later
lru-cache@11.2.6 BlueOak-1.0.0
minimatch@10.2.2 BlueOak-1.0.0
minipass@7.1.3 BlueOak-1.0.0
musl-utils@1.2.5-r21 GPL-2.0-or-later
node@25.8.1 no licenses found
npm@11.11.0 Artistic-2.0
path-scurry@2.0.2 BlueOak-1.0.0
qrcode-terminal@0.12.0 Apache 2.0
scanelf@1.3.8-r2 GPL-2.0-only
spdx-exceptions@2.5.0 CC-BY-3.0
spdx-license-ids@3.0.23 CC0-1.0
ssl_client@1.37.0-r30 GPL-2.0-only
tar@7.5.9 BlueOak-1.0.0
yallist@5.0.0 BlueOak-1.0.0
zlib@1.3.1-r2 Zlib

Remediation

  • Upgrade vulnerable packages to the fixed versions listed above where available; rebuild and re-pin the image digest.
  • For findings with no fixed version, monitor upstream advisories and track for a future patch release.
  • For license policy violations, review whether the flagged component is required; replace with a policy-compliant alternative, or add an explicit exception if the license is acceptable for this use case.

Generated by 🛡️ Daily Container Image Security Scan · sonnet50 · 331.8 AIC · ⌖ 8.81 AIC · ⊞ 5.9K ·

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions