dev-loop-dev-container
Warn
Audited by Socket on Jul 8, 2026
1 alert found:
AnomalyAnomalyreferences/devcontainer-setup.md
LOWAnomalyLOW
references/devcontainer-setup.md
No clear evidence of intentional malware in the shown configuration. However, the setup includes notable supply-chain and impact-amplification risks: it executes an unpinned remote script during Docker build, runs automated npm install/ci lifecycle hooks and a migration script, and bind-mounts the host’s SSH keys into the container. These factors would significantly increase harm if dependencies or upstream scripts were tampered with. Hardcoded Postgres credentials further weaken security hygiene for non-local use.
Confidence: 70%Severity: 66%
Audit Metadata