-
-
Notifications
You must be signed in to change notification settings - Fork 1.8k
Open
Labels
resolution/answeredresolution/awaiting-releasesecurityPull requests that address a security vulnerabilityPull requests that address a security vulnerabilitytype/question
Description
As of Test Containers v0.39.5 for Scala 2 (and I believe v0.39.7) our Snyk pipeline has reported the following vulnerabilities with transitive dependencies of Test Containers:
- JUnit @ 4.12: Information Exposure / Man-in-the-Middle
- Apache Commons Compress @ 1.18: Denial of Service
These both have a low priority score. If these are legitimate vulnerabilities is there a planned or available fix version for test containers?
Metadata
Metadata
Assignees
Labels
resolution/answeredresolution/awaiting-releasesecurityPull requests that address a security vulnerabilityPull requests that address a security vulnerabilitytype/question