docker-development
Warn
Audited by Socket on Sep 19, 2026
1 alert found:
SecuritySecurityexamples/docker-compose.sample.yml
MEDIUMSecurityMEDIUM
examples/docker-compose.sample.yml
The Compose file contains serious container security and secret-management weaknesses, especially Docker socket exposure, privileged execution, hardcoded credentials, broad host port exposure, host networking, and mutable image tags. These issues could enable host compromise or unauthorized access if a service is compromised. No direct evidence of malware, data exfiltration, persistence, or intentionally malicious code is present; the risks are configuration-based and appear deliberately included as scanner test cases.
Confidence: 99%Severity: 90%
Audit Metadata