typo3-testing
Warn
Audited by Socket on Mar 16, 2026
1 alert found:
AnomalyAnomalyassets/docker/docker-compose.yml
LOWAnomalyLOW
assets/docker/docker-compose.yml
No direct malware is present in this compose YAML fragment. However, it contains several insecure practices that raise the likelihood of accidental compromise or exploitation: hardcoded weak credentials (including root), publishing the database port to the host, and broad host filesystem mounts into containers. Also verify image tags to avoid accidental typosquatting. Treat this as a moderate security risk that needs remediation (use secrets, tighten network exposure, avoid wholesale repository mounts).
Confidence: 90%Severity: 60%
Audit Metadata