containers
Warn
Audited by Socket on Sep 11, 2026
1 alert found:
SecuritySecurityevals/files/deployment.yaml
MEDIUMSecurityMEDIUM
evals/files/deployment.yaml
The manifest does not contain evident malware or intentional sabotage. It does contain serious security weaknesses: hardcoded production credentials, including an apparent live Stripe key, and execution of an unpinned mutable :latest image. Replace credentials with Kubernetes Secrets or an external secret manager, rotate any exposed keys, pin the image by immutable digest, configure TLS explicitly, and migrate deprecated Kubernetes APIs. The configuration should be reviewed before production use.
Confidence: 98%Severity: 82%
Audit Metadata