containers

Warn

Audited by Socket on Sep 11, 2026

1 alert found:

Security
SecurityMEDIUM
evals/files/deployment.yaml

The manifest does not contain evident malware or intentional sabotage. It does contain serious security weaknesses: hardcoded production credentials, including an apparent live Stripe key, and execution of an unpinned mutable :latest image. Replace credentials with Kubernetes Secrets or an external secret manager, rotate any exposed keys, pin the image by immutable digest, configure TLS explicitly, and migrate deprecated Kubernetes APIs. The configuration should be reviewed before production use.

Confidence: 98%Severity: 82%
Audit Metadata
Analyzed At
Sep 11, 2026, 03:15 PM
Package URL
pkg:socket/skills-sh/lynricsy%2Fhyperskills%2Fcontainers%2F@cccc40122eac6c44d1a5057237a16cfa34a7e77252c4ebfe3dc91b0e4bd03ef3
Security Audit — socket — containers