Proof in the wild: ConfigSentry vs public compose files

A quick reality check: what shows up in real repositories.

2026-02-22

Safety / methodology

Full reports (with aggregate summaries): repo-tests/

What we found

Across the first three repos tested, the most common patterns were:

Try it yourself

npx configsentry ./docker-compose.yml

For CI gating: --severity-threshold high

Related pages: Compose security best practices · Docker Compose linter