docker
Audited by Socket on Sep 15, 2026
2 alerts found:
Anomalyx2No direct malicious behavior is present in the supplied documentation. The most significant issue is the claim that Docker `ARG` credentials do not persist: tokens used in `RUN` commands may be exposed through image history, build metadata, logs, or exported cache. Use BuildKit secret mounts for remote-cache credentials, pin and verify pnpm/turbo versions, and use a production-only dependency deployment for the runtime image. The fragment itself contains no obfuscated payload or evident malware.
No malware or deliberate supply-chain attack is evident. The examples contain security risks if used unchanged: plaintext and weak database credentials, publicly exposed database and Redis ports, plaintext environment-file secrets, broad development bind mounts, debug service exposure, and mutable image tags. These are configuration and operational risks rather than malicious behavior.