typo3-testing

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
assets/docker/docker-compose.yml

No direct malware is present in this compose YAML fragment. However, it contains several insecure practices that raise the likelihood of accidental compromise or exploitation: hardcoded weak credentials (including root), publishing the database port to the host, and broad host filesystem mounts into containers. Also verify image tags to avoid accidental typosquatting. Treat this as a moderate security risk that needs remediation (use secrets, tighten network exposure, avoid wholesale repository mounts).

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Mar 16, 2026, 02:26 PM
Package URL
pkg:socket/skills-sh/netresearch%2Ftypo3-testing-skill%2Ftypo3-testing%2F@8257f5ae620bf9a236764798f6e020747b2c7df5