data-lake-platform
Warn
Audited by Socket on Sep 23, 2026
1 alert found:
SecuritySecurityassets/query-engines/starrocks/template-starrocks-setup.md
MEDIUMSecurityMEDIUM
assets/query-engines/starrocks/template-starrocks-setup.md
No evidence of malware or intentional sabotage is present. The code is a readable StarRocks setup template, but it contains significant operational security weaknesses: mutable image tags, host-exposed database ports, an empty admin password in the stream-load example, plaintext external-catalog communication, and credentials embedded in catalog properties. These should be remediated before production use by pinning image digests, enforcing authentication and TLS, restricting network access, using a secrets manager, and validating replication against the actual cluster size.
Confidence: 98%Severity: 72%
Audit Metadata