Thanks for the feedback! LocalStack CTO here. Very timely - we're right now in the process of upgrading all dependencies (JAR files, etc) in our Docker images to reduce the exposure for potential vulnerabilities.
The scan results of the security scanning tool we're using look promising - they're almost green already.. :) Please let us know if there's anything particular that's blocking you from bringing it into your company! Appreciated