---
title: "dockerfile-compose-security"
description: "Blocks (some rules ask) when a change to a Dockerfile, Containerfile or compose file adds: a base image with no tag, latest, an unresolvable ARG or no digest (stage-aware: FROM or COPY --from a stage is not an image); a "
canonical: https://agentpluginsdirectory.com/plugins/dockerfile-compose-security--open-coder-ai
last-updated: 2026-10-06
---

# dockerfile-compose-security
Blocks (some rules ask) when a change to a Dockerfile, Containerfile or compose file adds: a base image with no tag, latest, an unresolvable ARG or no digest (stage-aware: FROM or COPY --from a stage is not an image); a final stage running as root; TLS or package-signature checks off; secret-named ENV/ARG/environment literals; COPY of key or.env files; remote ADD without checksum; fetch piped to a shell; RUN --security=insecure; chmod 777 or setuid; sudo, sshd, chpasswd; unpinned git clone; ONBUILD RUN; compose privileged, broad cap_add, unconfined profiles, devices, host namespaces, runtime socket or host-root mounts, database ports on every interface, untagged images. A one-line form is left to block-fetch-exec-in-files, block-unpinned-agent-components or agentic-code-security only where that gate is installed and reads the file; scan-secrets lines always. Misses: build args overriding defaults, commands in variables, aliases or $'' quoting, bake and k8s files. Friction, not a boundary.
- Slug: dockerfile-compose-security--open-coder-ai
- Publisher: chock-core
- Repository: https://github.com/open-coder-ai/chock-catalog
- Manifest: base/dockerfile-compose-security/plugin.json
- Version: 0.1.0
- License: Apache-2.0
- Category (editorial): other
- Skills: 1 (dockerfile-compose-security)
- MCP servers: 0
- Stars: 3
- Repository created: 2026-08-17
- Repository last pushed: 2026-10-06
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/dockerfile-compose-security--open-coder-ai
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## Skills

- dockerfile-compose-security: Blocks (some rules ask) when a change to a Dockerfile, Containerfile or compose file adds: a base image with no tag, latest, an unresolvable ARG or no digest (stage-aware: FROM or COPY --from a stage is not an image); a final stage running as root; TLS or package-signature checks off; secret-named…

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
