{"_id":"@agentlaunchopsai/compose-risk-guard","_rev":"2-9dddca363939a8b644f01a764df7fcab","name":"@agentlaunchopsai/compose-risk-guard","dist-tags":{"latest":"1.0.1"},"versions":{"1.0.0":{"name":"@agentlaunchopsai/compose-risk-guard","version":"1.0.0","keywords":["docker","compose","docker-compose","security","secrets","ci","linter"],"author":{"name":"AgentLaunchOps"},"license":"MIT","_id":"@agentlaunchopsai/compose-risk-guard@1.0.0","maintainers":[{"name":"agentlaunchops","email":"agentlaunchops@proton.me"}],"bin":{"compose-risk-guard":"src/cli.js"},"dist":{"shasum":"0ff3c1c426b728ca494b305757a3d635019f9280","tarball":"https://registry.npmjs.org/@agentlaunchopsai/compose-risk-guard/-/compose-risk-guard-1.0.0.tgz","fileCount":6,"integrity":"sha512-HMefCHDI3VrjoUFnnjZuzPdtfyBKzmVn8Dv2hSIWsZKkhE1Qn+2iN4Ez6sj8ErXrNX9+QgnuYKGVa/UJ62lZig==","signatures":[{"sig":"MEUCIQDwuUjqjUxB7k+8RLSLYtP84PvztOMuH16nPPvMxmjXgQIgW283FXMLNxOEY5Qj0jdY1UdFUd34ckbgRNuVXlTu+ZY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":14259},"type":"module","engines":{"node":">=18"},"gitHead":"3f35c282ad8db7955538fdbfd73b68dfebace8bb","scripts":{"scan":"node src/cli.js .","test":"node --test","prepublishOnly":"npm test && node src/cli.js . --no-fail"},"_npmUser":{"name":"agentlaunchops","email":"agentlaunchops@proton.me"},"_npmVersion":"11.13.0","description":"Scan Docker Compose files for secret env values and host-access risks.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"js-yaml":"^4.1.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/compose-risk-guard_1.0.0_1780867228502_0.731917908785799","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@agentlaunchopsai/compose-risk-guard","version":"1.0.1","description":"Scan Docker Compose files for secret env values and host-access risks.","type":"module","bin":{"compose-risk-guard":"src/cli.js"},"scripts":{"test":"node --test","scan":"node src/cli.js .","prepublishOnly":"npm test && node src/cli.js . --no-fail"},"keywords":["docker","compose","docker-compose","security","secrets","ci","linter"],"author":{"name":"AgentLaunchOps"},"license":"MIT","engines":{"node":">=18"},"dependencies":{"js-yaml":"^4.1.0"},"gitHead":"9b68d25cb77056ae542ac7ddbaf998fe0b5e9b2b","_id":"@agentlaunchopsai/compose-risk-guard@1.0.1","_nodeVersion":"24.16.0","_npmVersion":"11.13.0","dist":{"integrity":"sha512-ywwbWyUn7dGyS+t1fr4bGYIvtcrcENperHu6TmNlFEqxYokYCk52aT34NNkGb8gPEm640GotmEj4hYLQH6e4uA==","shasum":"17d7d1f1c6e28d9f6a2380053ea94b609be4b3df","tarball":"https://registry.npmjs.org/@agentlaunchopsai/compose-risk-guard/-/compose-risk-guard-1.0.1.tgz","fileCount":6,"unpackedSize":47190,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIGGdsuO8LfaRk9fjrxFXMyJdS6Wjcr4cUp2A0ULDTqSPAiBtZcsHg7PQlCr/uUVBnYIQ19ZuUa0ssgXJtfaKOs80oQ=="}]},"_npmUser":{"name":"agentlaunchops","email":"agentlaunchops@proton.me"},"directories":{},"maintainers":[{"name":"agentlaunchops","email":"agentlaunchops@proton.me"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/compose-risk-guard_1.0.1_1781635472462_0.9709682791494842"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-07T21:20:28.370Z","modified":"2026-06-16T18:44:32.723Z","1.0.0":"2026-06-07T21:20:28.659Z","1.0.1":"2026-06-16T18:44:32.607Z"},"author":{"name":"AgentLaunchOps"},"license":"MIT","keywords":["docker","compose","docker-compose","security","secrets","ci","linter"],"description":"Scan Docker Compose files for secret env values and host-access risks.","maintainers":[{"name":"agentlaunchops","email":"agentlaunchops@proton.me"}],"readme":"# Compose Risk Guard\n\nCompose Risk Guard scans Docker Compose files for secret-like environment values\nand host-access settings that are easy to miss in review.\n\nIt checks for:\n\n- secret-looking `environment` entries with literal values\n- secret-looking keys inside referenced env files\n- `privileged: true`\n- Docker socket bind mounts\n- host namespace sharing through `network_mode`, `pid`, or `ipc`\n- bind mounts of sensitive host paths\n- bind mounts of local credential files such as `.env`, `.npmrc`, private keys,\n  and certificate bundles\n- unpinned or `latest` image tags\n\n## Install\n\n```sh\nnpm install -g @agentlaunchopsai/compose-risk-guard\n```\n\n## Use\n\n```sh\ncompose-risk-guard .\ncompose-risk-guard --file ci/docker-compose.review.yml\ncompose-risk-guard . --format=json\ncompose-risk-guard . --ignore-rule=CRG007\ncompose-risk-guard . --json\ncompose-risk-guard . --sarif\ncompose-risk-guard . --summary\ncompose-risk-guard . --markdown\ncompose-risk-guard . --junit\ncompose-risk-guard . --csv\ncompose-risk-guard . --github-annotations\ncompose-risk-guard . --gitlab-code-quality\ncompose-risk-guard . --exit-code\ncompose-risk-guard . --count\ncompose-risk-guard . --min-severity=error\ncompose-risk-guard . --fail-on=error\ncompose-risk-guard . --json --max-findings=25\ncompose-risk-guard . --sarif --output=reports/compose-risk-guard.sarif\ncompose-risk-guard . --quiet\ncompose-risk-guard . --no-fail\ncompose-risk-guard --rules\ncompose-risk-guard --formats\ncompose-risk-guard --metadata\ncompose-risk-guard --example-config\ncompose-risk-guard --ci-snippet=github-actions\ncompose-risk-guard --ci-snippet=gitlab-ci\ncompose-risk-guard --ci-snippet=circleci\ncompose-risk-guard --ci-snippet=pre-commit\ncompose-risk-guard --completion=bash\ncompose-risk-guard --version\nnpx @agentlaunchopsai/compose-risk-guard .\n```\n\nBy default it scans common Compose filenames such as `compose.yml`,\n`compose.yaml`, `docker-compose.yml`, and `docker-compose.yaml`.\n\nUse `--file=path/to/compose.yml` to scan one explicit Compose file instead of\nrecursively discovering Compose files under a directory. This is useful for\npre-commit hooks, changed-file CI jobs, and monorepos that already know which\nCompose file needs review.\n\nUse `--format=<name>` to select an output format from a single parameter. It\naccepts `text`, `json`, `sarif`, `summary`, `markdown`, `junit`, `csv`,\n`github-annotations`, `gitlab-code-quality`, `exit-code`, and `count`. This is\nuseful for reusable CI templates that pass the report format as an environment\nor matrix value.\n\nUse `--ignore-rule=<ID>` to suppress one or more rule IDs before reporting and\nexit-code decisions. Repeat the option or comma-separate values, such as\n`--ignore-rule=CRG007 --ignore-rule=CRG008` or\n`--ignore-rule=CRG007,CRG008`. This is useful when a rollout needs to keep\nenforcing critical host-access checks while temporarily accepting a documented\nimage-tag or credential-mount exception.\n\nUse `--rules` to print the rule ID, default severity, and description without\nscanning the current directory. This is useful for CI policy docs and allowlist\nreviews that need stable rule identifiers.\n\nUse `--formats` to print the supported `--format=<name>` values without scanning\nthe current directory. This is useful for reusable CI templates and wrapper\nscripts that validate user-selected report formats before running a scan.\n\nUse `--metadata` to print package version, supported output formats, and rule\nIDs as JSON without scanning the current directory. This is useful for generated\nCI templates, dashboards, and wrapper scripts that need one stable discovery\npayload.\n\nUse `--example-config` to print a GitHub Actions starter workflow without\nscanning the current directory. This is useful when bootstrapping a repository\nor generating CI setup instructions from an installed CLI.\n\nUse `--ci-snippet=github-actions`, `--ci-snippet=gitlab-ci`,\n`--ci-snippet=circleci`, or `--ci-snippet=pre-commit` to print a copy-pasteable\nintegration snippet without scanning the current directory. This is useful for\nsetup docs, generators, release checks, and local hook templates that need a\nsmaller fragment than the full starter workflow.\n\nUse `--completion=bash` to print a Bash completion script without scanning the\ncurrent directory. This is useful for install scripts and shell setup docs that\nwant tab completion for supported CLI options.\n\nUse `--version` to print the installed package version without scanning the\ncurrent directory. This is useful in CI diagnostics and release verification\nlogs.\n\nUse `--summary` to print compact finding counts by severity and rule. This is\nuseful for CI logs, scheduled scans, and dashboards that need a small status\nline without full finding details.\n\nUse `--markdown` to print a Markdown findings table for pull request comments,\nissue reports, or CI job summaries that should stay readable without a SARIF\nviewer.\n\nUse `--junit` to print JUnit XML so CI systems can publish Compose findings as\ntest report failures. Pair it with `--no-fail` when a pipeline should collect\nthe report artifact before applying its own pass/fail gate.\n\nUse `--csv` to print finding rows for spreadsheets, warehouse imports, and\nportfolio dashboards that need plain tabular data without a SARIF parser.\n\nUse `--min-severity=error` to emit only error-level findings. The default is\n`--min-severity=warning`, which preserves the normal warning-plus-error output.\nThis is useful when rolling out the scanner in advisory mode before enforcing\nwarning-level policy.\n\nUse `--fail-on=error` to keep warning output visible while exiting nonzero only\nwhen error-level findings are present. The default is `--fail-on=warning`, which\npreserves the existing behavior where any emitted finding fails the command.\n\nUse `--max-findings=25` to cap detailed report output for noisy repositories\nwhile keeping the exit status tied to the full filtered scan result. Summary\noutput still counts every finding so CI logs can show the real blast radius.\n\nUse `--output=path/to/report` to write any selected report format to a file\ninstead of stdout. Parent directories are created automatically, which keeps CI\nsteps simple when producing SARIF, JUnit, CSV, or code-quality artifacts.\n\nUse `--github-annotations` to print GitHub Actions workflow commands that place\nCompose findings inline on changed files. Pair it with `--no-fail` when you\nwant annotations without blocking a pull request yet.\n\nUse `--gitlab-code-quality` to print GitLab Code Quality report JSON for the\n`artifacts:reports:codequality` pipeline feature. Pair it with `--no-fail` when\nthe pipeline should upload the report before applying a separate failure gate.\n\nUse `--exit-code` to print the numeric exit-code decision (`0` or `1`) while\nstill exiting with that same status. Pair it with `--no-fail` when a wrapper\nscript needs the advisory-mode decision as a plain value.\n\nUse `--count` to print only the filtered finding count. This is useful for CI\nmetrics, shell gates, and scheduled scans that need a tiny numeric signal.\n\nUse `--quiet` to suppress the default clean \"no findings\" stdout line while\nkeeping findings and exit status unchanged. Explicit report formats such as\n`--json`, `--sarif`, `--summary`, `--count`, and `--exit-code` still print their\nmachine-readable output.\n\n## CI\n\n```yaml\nname: compose-risk-guard\non:\n  pull_request:\n  push:\n    branches: [main]\n\njobs:\n  scan:\n    runs-on: ubuntu-latest\n    permissions:\n      contents: read\n      security-events: write\n    steps:\n      - uses: actions/checkout@v4\n      - uses: actions/setup-node@v4\n        with:\n          node-version: \"20\"\n      - run: npx -y @agentlaunchopsai/compose-risk-guard . --sarif --no-fail > compose-risk-guard.sarif\n      - uses: github/codeql-action/upload-sarif@v3\n        with:\n          sarif_file: compose-risk-guard.sarif\n```\n\n## Rules\n\n| Rule | Check |\n| --- | --- |\n| `CRG001` | Secret-like environment variable has a literal value |\n| `CRG002` | Referenced env file contains a secret-like literal |\n| `CRG003` | Service runs with `privileged: true` |\n| `CRG004` | Service bind-mounts the Docker socket |\n| `CRG005` | Service shares a host namespace |\n| `CRG006` | Service bind-mounts a sensitive host path |\n| `CRG007` | Service image uses `latest` or has no explicit tag/digest |\n| `CRG008` | Service bind-mounts a local credential file |\n\n## Related security tooling\n\nIf you also use GitHub Actions, [`gha-guard`](https://www.npmjs.com/package/@agentlaunchopsai/gha-guard)\n(`npx @agentlaunchopsai/gha-guard`) applies the same idea to your CI: it flags unpinned action\nSHAs, over-broad `GITHUB_TOKEN` permissions, and script injection. Free, same author.\n\nFor a deeper, maintained rule set plus remediation playbooks, see the optional\n[GHA Guard Pro Kit](https://launchagent.gumroad.com/l/auqpvm?utm_source=compose-risk-guard&utm_medium=readme&utm_campaign=pro) ($29).\n\n## License\n\nMIT\n","readmeFilename":"README.md"}