Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

🚨 Security: Critical or high vulnerabilities in mcp-server-time container

オープン
#1,042 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
62/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
活発
技術スタック
docker, github-actions, python

調査の方向性

mcp-server-time イメージが Python 依存関係をどこでピン留めしているか特定し(リポジトリ内で pyjwt/2.13.0、および ghcr.io/stacklok/dockyard/uvx/mcp-server-time に供給する Dockerfile またはロックマニフェストを検索)、periodic-security-scan ワークフローでイメージがどのようにビルドされ再スキャンされるか確認する。GHSA-ffc3-869f-jxw9 および 5 件の high アドバイザリを修正するリリースに pyjwt をアップグレードし、再ビルドして、code-scanning に検出結果がクリアされたことが表示され、ビルドワークフローが公開できることを確認する。

索引モデルが issue の本文から書いたものです。

説明

critical grype high security

🚨 Security Scan Alert

A periodic security scan found fixable critical or high severity vulnerabilities in the container image. Findings at this level also block publishing in the build workflow.

  • Image: ghcr.io/stacklok/dockyard/uvx/mcp-server-time:2026.8.18
  • Critical vulnerabilities: 1
  • High vulnerabilities: 5
Details

See the Security tab for full details.

Critical Vulnerabilities
  • GHSA-ffc3-869f-jxw9 in [email protected]: PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard
High Vulnerabilities
  • GHSA-r6x4-923q-g947 in [email protected]: PyJWT BOM Bypass
  • GHSA-w2cx-738m-mc7w in [email protected]: PyJWT accepts public JWK containers as HMAC secrets
  • GHSA-9j54-fg26-wv3r in [email protected]: PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation
  • GHSA-p4g4-x82p-q773 in [email protected]: PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard
  • GHSA-9v7f-9g4p-ffgj in [email protected]: PyJWT: PyJWKClient follows redirects when fetching JWKS

Automated security scan from periodic-security-scan workflow

主要言語
Go
スター
8
フォーク
7
平均マージ
1日 17時間
マージ済み PR(30日)
114

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

stacklok/dockyard のほかの issue

stacklok/dockyard の issue をすべて見る

似ている issue

Go の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。