migrate-to-openchoreo
Warn
Audited by Socket on Aug 24, 2026
1 alert found:
AnomalyAnomalyreferences/sample-types/resource-types/postgres.yaml
LOWAnomalyLOW
references/sample-types/resource-types/postgres.yaml
No clear indicators of stealthy supply-chain malware or credential exfiltration are present in this template fragment. However, it intentionally creates a known PostgreSQL SUPERUSER with a hardcoded weak password (`demo`/`demo`), optionally exposes Adminer externally via gateway routing, and generates convenience connection URLs that embed passwords and disable SSL. These are significant security risks if enabled beyond a strictly controlled demo environment.
Confidence: 68%Severity: 60%
Audit Metadata