docker — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited docker (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Project-specific containerization patterns for Dockerfile and Docker Compose.
condition: service_healthy.COPY . . before RUN npm install busts the cache on EVERY code change. Copy package*.json first, install, THEN copy source.apk add build dependencies. Consider -slim variants if you hit this.ENTRYPOINT ["python", "app.py"] (exec form) handles signals correctly. ENTRYPOINT python app.py (shell form) wraps in /bin/sh -c and PID 1 won't receive SIGTERM — containers take 10s to stop.COPY near the top rebuilds everything below it.depends_on without condition: service_healthy only waits for container START, not readiness. Your app will crash connecting to a database that's still initializing.host.docker.internal works on Docker Desktop (Mac/Windows) but NOT on Linux. Use --network host or explicit container networking on Linux.ARG) are NOT available after FROM in multi-stage builds unless re-declared. Each stage starts fresh.docker compose up reuses existing containers. After changing Dockerfile, you need docker compose up --build or docker compose build first.node_modules are built inside the container but you mount .:/app, the host's (possibly empty) node_modules shadows them. Use a named volume for node_modules.EXPOSE is documentation only — it does NOT publish the port. You still need -p 8080:8080 or ports: in compose.| When you need... | Read |
|---|---|
| Dockerfile patterns, CMD vs ENTRYPOINT | dockerfile.md |
| Compose services, networks, volumes | compose.md |
| Security hardening | security.md |
| Production deployment | production.md |
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.