deepstream-import-vision-model
Warn
Audited by Socket on Sep 8, 2026
1 alert found:
AnomalyAnomalyscripts/dsrun.sh
LOWAnomalyLOW
scripts/dsrun.sh
This fragment is a straightforward Docker-based command runner with no direct evidence of embedded malware, secrets, obfuscation, or exfiltration. The main supply-chain/security risk is the intentional passthrough of caller-controlled command text into bash -lc and the ability to override the executed container image via DS_IMAGE. When used in CI or automation with any untrusted inputs, it can enable arbitrary in-container code execution and manipulation of the bind-mounted host working directory.
Confidence: 70%Severity: 52%
Audit Metadata