docker-claude/claude
docker-claude eb5f240d3e fix(docker): patch transitive CVEs in MCP server dependencies
MCP servers bundle their own copies of vulnerable packages. After global
install, patch nested node_modules in each server directly:
- @modelcontextprotocol/sdk 1.0.1 → 1.25.2 (CVE-2025-66414, CVE-2026-0621)
- picomatch 4.0.3 → 4.0.4 (CVE-2026-33671)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-20 15:28:20 +02:00
..
Dockerfile fix(docker): patch transitive CVEs in MCP server dependencies 2026-04-20 15:28:20 +02:00
settings.json feat(mcp): add GitHub, GitLab, Jira, and Confluence MCP servers 2026-04-14 23:09:42 +02:00