Input is processed only in the active browser tab's memory and is not sent to a ByteQuant server.
Dockerfile Security Pre-check
Flag root user, floating tags, copied secrets, broad permissions, and cache residue by line. It scans explainable patterns without executing code; it is not complete SAST, antivirus, package reputation, or proof of exploitability.
Output will appear here. Load the example to try the tool immediately.
Input and output are not stored. The optional usage counter keeps only tool identity and count, never content.
Output comes from disclosed rules or browser APIs and needs independent review before high-impact use.
A result in three steps
- 01
Enter authorized code or configuration.
- 02
Run the bounded local pre-scan.
- 03
Verify findings against context and official documentation.
When is this tool useful?
- ✓ Pre-review scanning
- ✓ Configuration hardening
- ✓ Risk prioritization
Automated output is a preliminary assessment. Do not use it alone for legal, financial, medical, or security-critical decisions.
Guides for this tool
Local Supply-Chain Pre-checks for Packages, npm Scripts, Dockerfiles, and CI
Find high-value risk signals without execution and prioritize manual review.
Read guide →Frequently asked questions
Does this tool send input to a server?+
No. Processing runs in this browser tab. Data leaves the page only when you choose to copy or download the result.
Is the result definitive?+
The tool produces consistent output from disclosed rules and browser APIs, but context, data quality, and method limitations can affect it. Verify high-impact decisions.
Is input saved?+
No. Tool input is not persisted. With consent, only tool identity and usage count may be kept on this device for personal shortcuts.