CI and build security toolsLocal review / optional AI
CI and build security / FREE TOOL
Dockerfile review
Check base-image references, runtime user declarations, installation patterns, and secret-bearing build settings.
02 Your results
A closer look starts here.
Add your input and run the check. We will show the observations and explain what needs review.
A QUICK WALKTHROUGH
How to use it
- 01Paste a Dockerfile; replace any real credentials with placeholders.
- 02Review base-image, user and build-step signals.
- 03Verify behavior in an isolated build and the actual deployment configuration.
What this check can tell you
Reviews supported Dockerfile declarations without building an image or inspecting its layers. Base-image users, included scripts, build arguments and actual runtime policy remain unknown. Heredocs and nonstandard escape directives are unsupported.
The initial review processes files in this tab. If you choose the optional AI summary, the displayed findings are sent to Cloudflare AI; your raw file, result tables and decoded token claims are excluded.
Docker building best practices