migrate-to-openchoreo

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Anomaly
AnomalyLOW
references/sample-types/resource-types/postgres.yaml

No clear indicators of stealthy supply-chain malware or credential exfiltration are present in this template fragment. However, it intentionally creates a known PostgreSQL SUPERUSER with a hardcoded weak password (`demo`/`demo`), optionally exposes Adminer externally via gateway routing, and generates convenience connection URLs that embed passwords and disable SSL. These are significant security risks if enabled beyond a strictly controlled demo environment.

Confidence: 68%Severity: 60%
Audit Metadata
Analyzed At
Aug 24, 2026, 06:02 PM
Package URL
pkg:socket/skills-sh/openchoreo%2Fskills%2Fmigrate-to-openchoreo%2F@e4a90bc458c6e29d429c57f53f1c26576bb6b33d65e5b5411f173da0e9419679
Security Audit — socket — migrate-to-openchoreo