Tool Open source
compose-lint is a security-focused static-analysis linter for Docker Compose files such as docker-compose.yml and compose.yaml. It checks for privileged containers, missing capability restrictions, host namespace or network sharing, wildcard port bindings, unpinned images, Docker socket and sensitive host-path mounts, plaintext credentials, and related misconfigurations, with rules grounded in the OWASP Docker Security Cheat Sheet and CIS Docker Benchmark.
The Python tool runs locally or in CI, can export SARIF results, and provides mechanical fixes for unambiguous findings with a dry-run preview. It is distributed through PyPI, can also be run ad hoc with uvx or pipx, and has a multi-architecture Docker image that runs as a non-root user.
1 use taken from transcripts — each links to the moment in the video.
Checks Docker Compose files for security problems such as privileged containers, exposed ports, Docker socket mounts, unpinned images, and embedded credentials. It runs locally or in CI, exports SARIF, and previews mechanical fixes.
1 in the library.