🚨 Security Scan Alert
A periodic security scan found fixable critical or high severity vulnerabilities in the container image. Findings at this level also block publishing in the build workflow.
- Image:
ghcr.io/stacklok/dockyard/uvx/mcp-server-git:2026.8.18
- Critical vulnerabilities: 1
- High vulnerabilities: 7
Details
See the Security tab for full details.
Critical Vulnerabilities
- GHSA-ffc3-869f-jxw9 in
pyjwt@2.13.0: PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard
High Vulnerabilities
- GHSA-g5vv-9gxw-82hx in
gitpython@3.1.59: GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer field parsing
- GHSA-239g-whfq-7xj9 in
gitpython@3.1.59: GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution
- GHSA-r6x4-923q-g947 in
pyjwt@2.13.0: PyJWT BOM Bypass
- GHSA-w2cx-738m-mc7w in
pyjwt@2.13.0: PyJWT accepts public JWK containers as HMAC secrets
- GHSA-9j54-fg26-wv3r in
pyjwt@2.13.0: PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation
... and 2 more. See Security tab for complete list.
Automated security scan from periodic-security-scan workflow
🚨 Security Scan Alert
A periodic security scan found fixable critical or high severity vulnerabilities in the container image. Findings at this level also block publishing in the build workflow.
ghcr.io/stacklok/dockyard/uvx/mcp-server-git:2026.8.18Details
See the Security tab for full details.
Critical Vulnerabilities
pyjwt@2.13.0: PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guardHigh Vulnerabilities
gitpython@3.1.59: GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer field parsinggitpython@3.1.59: GitPython: Repository content can impersonate the git directory, leading to arbitrary code executionpyjwt@2.13.0: PyJWT BOM Bypasspyjwt@2.13.0: PyJWT accepts public JWK containers as HMAC secretspyjwt@2.13.0: PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation... and 2 more. See Security tab for complete list.
Automated security scan from periodic-security-scan workflow