dokploy-docker-compose

Warn

Audited by Socket on May 16, 2026

1 alert found:

Security
SecurityMEDIUM
references/signoz-example.md

No clear evidence of intentional malicious behavior (e.g., explicit backdoors, exfiltration, or reverse shells) is present in the snippet. However, the deployment has a significant supply-chain integrity gap: the init container downloads and installs an executable from GitHub Releases but does not enforce checksum/signature verification in the active path, enabling tampered or corrupted artifacts to be executed via the ClickHouse user_scripts mount. Additional high-impact hardening concerns include remote-management capabilities in the OpAMP manager config, empty ClickHouse default password with broad network access, and Zookeeper anonymous login. Overall, the module warrants security review and hardening before production use.

Confidence: 63%Severity: 72%
Audit Metadata
Analyzed At
May 16, 2026, 04:20 PM
Package URL
pkg:socket/skills-sh/trfi%2Fskills%2Fdokploy-docker-compose%2F@0c15b3976004885b5c8ad11986c73aff4f7a0349
Security Audit — socket — dokploy-docker-compose