setup-container-registry
Fail
Audited by Socket on Feb 27, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
The material is a comprehensive, well-aligned guide for configuring and securing container registries across ghcr.io, Docker Hub, and Harbor. The primary risk is exposure of credentials and secrets through example configurations and documentation. An improved version should replace hardcoded secrets with placeholders, enforce secret management best practices, pin tool versions and verify integrity, and document rotation and access controls. Overall, the plan is sound if secret handling and tool verification are addressed to reduce supply-chain and access risks.
Confidence: 98%Severity: 90%
Audit Metadata