docker

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Anomaly
AnomalyLOW
references/compose.md

The fragment is ordinary Docker Compose documentation and does not contain evident malware or intentional malicious behavior. It has meaningful deployment security risks: weak example credentials, unauthenticated Redis, broadly published infrastructure ports, bind-mounted source/configuration files, and mutable unpinned container images. The configuration also contains apparent port interpolation syntax errors. These issues should be corrected before production use, but the code itself provides no evidence of a supply-chain backdoor.

Confidence: 99%Severity: 68%
Audit Metadata
Analyzed At
Sep 18, 2026, 07:28 PM
Package URL
pkg:socket/skills-sh/stifleur390%2Ffullstack-dev-skills%2Fdocker%2F@0ae7c2b2f685d456add737381345cb383f88c25d21757e27aad63a990bd4804d
Security Audit — socket — docker