Skip to content

Reported Vulnerabilities from Transitive Dependencies #4456

@jonathan-neufeld-asurion

Description

As of Test Containers v0.39.5 for Scala 2 (and I believe v0.39.7) our Snyk pipeline has reported the following vulnerabilities with transitive dependencies of Test Containers:

  • JUnit @ 4.12: Information Exposure / Man-in-the-Middle
  • Apache Commons Compress @ 1.18: Denial of Service

These both have a low priority score. If these are legitimate vulnerabilities is there a planned or available fix version for test containers?

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions