proj-deploy

Warn

Audited by Socket on Sep 23, 2026

1 alert found:

Security
SecurityMEDIUM
docker-compose.md

No direct malicious behavior is evident in the supplied Compose files. The principal security risks are exposed database and infrastructure ports, unauthenticated development Redis, the hardcoded Grafana password admin, secret exposure through environment variables and command arguments, broad host bind mounts, and non-immutable image tags. These issues should be remediated before production deployment, but the fragment alone does not demonstrate malware.

Confidence: 98%Severity: 72%
Audit Metadata
Analyzed At
Sep 23, 2026, 10:09 AM
Package URL
pkg:socket/skills-sh/zhangloveyan%2Fbackend-skill%2Fproj-deploy%2F@41532ee9cdcd53c8ee4e126b3ab5060373a0796764a815c6dd3d987d63f0744d
Security Audit — socket — proj-deploy