Closed
- Remove mcp-servers block from shared/mcp/semgrep.md following the brave.md pattern for containers with unpatched upstream CVEs - Disable daily schedule in daily-semgrep-scan.md until a patched semgrep image is published upstream - Remove semgrep/semgrep:latest pin from actions-lock.json - Recompile all affected workflow lock files Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot
AI
changed the title
[WIP] Update semgrep/semgrep image to address vulnerabilities
fix(security): disable semgrep/semgrep container — Critical/High CVEs, no upstream fix available
Closed
Closed
pelikhan marked this pull request as ready for review
August 2, 2026 13:55Copilot AI review requested due to automatic review settings
August 2, 2026 13:55pelikhan deleted the copilot/container-image-scan-remediation-again branch
August 2, 2026 13:55Merged