dokploy-docker-compose

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
references/signoz-example.md

This is a legitimate-looking SigNoz deployment configuration, not clear malware. The primary supply-chain risk is execution of an externally downloaded binary as root without checksum or signature verification. The default JWT secret and publicly exposed plaintext services are additional security weaknesses. Pin and verify the artifact, require a strong JWT secret, and restrict or secure published ports before production use.

Confidence: 93%Severity: 68%
Audit Metadata
Analyzed At
Sep 17, 2026, 11:56 PM
Package URL
pkg:socket/skills-sh/trfi%2Fskills%2Fdokploy-docker-compose%2F@6a1b65ee145db26ed5554055cfe538853666e7697f20036b07ee1c268183b0bd
Security Audit — socket — dokploy-docker-compose