typo3-testing

Warn

Audited by Socket on May 6, 2026

1 alert found:

Anomaly
AnomalyLOW
assets/docker/docker-compose.yml

No direct malware is present in this compose YAML fragment. However, it contains several insecure practices that raise the likelihood of accidental compromise or exploitation: hardcoded weak credentials (including root), publishing the database port to the host, and broad host filesystem mounts into containers. Also verify image tags to avoid accidental typosquatting. Treat this as a moderate security risk that needs remediation (use secrets, tighten network exposure, avoid wholesale repository mounts).

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
May 6, 2026, 11:32 AM
Package URL
pkg:socket/skills-sh/netresearch%2Ftypo3-testing-skill%2Ftypo3-testing%2F@54bebe8b2fd25311ef3aba8485154694bd1958c9
Security Audit — socket — typo3-testing