upgrade-project

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Anomaly
AnomalyLOW
references/frameworks/nestjs/dockerfile.md

No direct malware or overt sabotage is evident in the supplied Dockerfile. It does contain meaningful supply-chain and build-security risks: unauthenticated HTTP APT repositories, unpinned global npm installations, unpinned PM2 tooling, and possible .npmrc credential exposure through pnpm config list. Pin repositories and packages using HTTPS, digests or verified versions, avoid printing configuration containing credentials, review the env contents, and minimize production packages.

Confidence: 96%Severity: 62%
Audit Metadata
Analyzed At
Sep 9, 2026, 02:51 PM
Package URL
pkg:socket/skills-sh/jybill%2Fxqv-skills%2Fupgrade-project%2F@d3feb9e4ffabcd58d4e3643684e420b572db5fe2f64212cc85f16d6a26e23d90
Security Audit — socket — upgrade-project