# Policy Check Report ## Summary - Compose files checked: 29 - Critical findings: 0 - Warnings: 1 - Info findings: 13 ## Critical - none ## Warnings - [USER001] monitoring\docker-compose.yml :: influxdb3-core: Runs as user 0. Documented exception, keep visible for hardening. ## Info - [PORT001] core\gitea\docker-compose.yml :: gitea: Allowed host port mapping: 222:22 - [PORT001] host-services\Adguard\docker-compose.yml :: adguard: Allowed host port mapping: 53:53/tcp - [PORT001] host-services\Adguard\docker-compose.yml :: adguard: Allowed host port mapping: 53:53/udp - [PORT001] host-services\Adguard\docker-compose.yml :: adguard: Allowed host port mapping: 100.80.98.33:8082:80 - [HOSTNET001] host-services\plex\docker-compose.yml :: plex: network_mode: host is a documented exception. - [HOSTNET001] host-services\tailscale\docker-compose.yml :: tailscale: network_mode: host is a documented exception. - [IMAGE002] infra\ddns-updater\docker-compose.yml :: ddns-updater: Image uses a latest tag but is digest-pinned and documented as an exception. - [PORT001] monitoring\docker-compose.yml :: influxdb3-core: Allowed host port mapping: ${INFLUXDB_BIND_IP:-127.0.0.1}:8181:8181 - [IMAGE002] ops\glances\docker-compose.yml :: glances: Image uses a latest tag but is digest-pinned and documented as an exception. - [IMAGE002] ops\scrutiny\docker-compose.yml :: scrutiny: Image uses a latest tag but is digest-pinned and documented as an exception. - [PRIV001] ops\scrutiny\docker-compose.yml :: scrutiny: Privileged mode is a documented exception. - [PORT001] traefik\docker-compose.yml :: traefik: Allowed host port mapping: 80:80 - [PORT001] traefik\docker-compose.yml :: traefik: Allowed host port mapping: 443:443