testcontainers / testcontainers/testcontainers-java

Reported Vulnerabilities from Transitive Dependencies

Open
#4,456 6 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

resolution/answered resolution/awaiting-release security type/question
Dominant language
Java
Stars
8.7k
Forks
1.9k
Avg merge
2d 17h
Merged PRs (30d)
9

Description

As of Test Containers v0.39.5 for Scala 2 (and I believe v0.39.7) our Snyk pipeline has reported the following vulnerabilities with transitive dependencies of Test Containers:

  • JUnit @ 4.12: Information Exposure / Man-in-the-Middle
  • Apache Commons Compress @ 1.18: Denial of Service

These both have a low priority score. If these are legitimate vulnerabilities is there a planned or available fix version for test containers?

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files or tests are named. Start by inspecting the dependency tree for the reported Testcontainers Scala 2 versions and verify the Snyk findings for JUnit 4.12 and Apache Commons Compress 1.18. Done means the vulnerabilities are confirmed or dismissed and a fix version or dependency update path is documented.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.