upgrade-project
Warn
Audited by Socket on Sep 9, 2026
1 alert found:
AnomalyAnomalyreferences/frameworks/nestjs/dockerfile.md
LOWAnomalyLOW
references/frameworks/nestjs/dockerfile.md
No direct malware or overt sabotage is evident in the supplied Dockerfile. It does contain meaningful supply-chain and build-security risks: unauthenticated HTTP APT repositories, unpinned global npm installations, unpinned PM2 tooling, and possible .npmrc credential exposure through pnpm config list. Pin repositories and packages using HTTPS, digests or verified versions, avoid printing configuration containing credentials, review the env contents, and minimize production packages.
Confidence: 96%Severity: 62%
Audit Metadata