typo3-testing

Warn

Audited by Socket on May 20, 2026

1 alert found:

Anomaly
AnomalyLOW
assets/docker/docker-compose.yml

No direct malware is present in this compose YAML fragment. However, it contains several insecure practices that raise the likelihood of accidental compromise or exploitation: hardcoded weak credentials (including root), publishing the database port to the host, and broad host filesystem mounts into containers. Also verify image tags to avoid accidental typosquatting. Treat this as a moderate security risk that needs remediation (use secrets, tighten network exposure, avoid wholesale repository mounts).

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
May 20, 2026, 08:05 AM
Package URL
pkg:socket/skills-sh/dirnbauer%2Fwebconsulting-skills%2Ftypo3-testing%2F@8bccdc1e3ec8c594c0c7f212a2c9a0a6ea5552e6
Security Audit — socket — typo3-testing