dokploy-docker-compose
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
AnomalyAnomalyreferences/signoz-example.md
LOWAnomalyLOW
references/signoz-example.md
This is a legitimate-looking SigNoz deployment configuration, not clear malware. The primary supply-chain risk is execution of an externally downloaded binary as root without checksum or signature verification. The default JWT secret and publicly exposed plaintext services are additional security weaknesses. Pin and verify the artifact, require a strong JWT secret, and restrict or secure published ports before production use.
Confidence: 93%Severity: 68%
Audit Metadata