Skip to content

Repository files navigation

Container Check — Dispersal Wolves

Container Check

Review container definitions before they become exposure.

Audits normalized Docker Compose configuration for dangerous privileges, mounts, capabilities, networking, ports, images, and embedded secrets.

Start

node src/container-check.js scan compose.yaml

Run the command with --help for every option. The tool works locally, collects no telemetry, and supports machine-readable output where applicable.

Principles

  • Local first. Host data stays on the host unless you explicitly configure a webhook.
  • Safe by default. Inspection is read-only and mutation requires a deliberate command.
  • Small contract. The tool solves one defensive job and reports its limits plainly.
  • Scriptable. Stable exit codes and structured output make automation practical.

Platform

The initial release targets Linux. Portable behavior is also tested on Windows where the underlying operating-system facilities allow it. See the threat model for trust boundaries and non-goals.

Development

This repository uses Node.js without runtime dependencies. JSON Compose models can be scanned directly; YAML is normalized through the installed docker compose command before inspection.

npm ci
npm test
npm run lint

License

MIT © Dispersal Wolves.

About

Audit Docker Compose configurations for risky privileges, mounts, ports, images, and secrets.

Topics

Resources

Contributing

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages