12-factor-app
Audited by Socket on Sep 16, 2026
2 alerts found:
Anomalyx2The content is legitimate operational documentation, not malicious package code. It contains no obfuscation, exfiltration, persistence, or sabotage logic. However, production REPL access is intrinsically high privilege and can expose sensitive data or alter application state. The examples should be used only with strong authentication, authorization, auditing, read-only credentials where possible, and carefully controlled change procedures.
No malicious behavior or obfuscated payload is evident. The documentation presents a legitimate developer-operations model, but the example workflow and production-access guidance could create substantial security risk if implemented without protected branches, deployment approvals, environment-scoped secrets, least-privilege Kubernetes RBAC, audited access, and controlled migration procedures.