docker-workflow

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
examples/docker-compose.yml

The file itself is configuration and does not contain explicit malicious code, obfuscated payloads, or direct backdoors. However it contains multiple insecure configurations (hard-coded weak credentials, exposed management ports, disabled Elasticsearch security, host volume mounts that run init scripts) that increase the risk of compromise or data exposure. Treat this as a moderate security risk that requires remediation of secrets, network exposure, image pinning and volume isolation before production use.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Apr 1, 2026, 08:45 AM
Package URL
pkg:socket/skills-sh/bossjones%2Fboss-file-utils%2Fdocker-workflow%2F@956710fe9798fa2e2a9c2617fab34a423af1dbe2