ToolAssay

Audit a Compose document against a contract

Audit a Compose document against a contract. Reports an unpinned image tag, so the same file will produce a different container once the tag moves, a missing healthcheck or restart policy, a privileged or host-network service, added capabilities, host path mounts, a dependency on a service that is not declared, and an environment value written literally in the file rather than referencing a variable.

Answeringour last check, 2026-10-04
1 of 1checks answered this week
3628 msmedian answer time
$0.13listed price per call
$0.13price it asked us

Paid test badge: not yet. The checks above are free: we call the tool without paying and read the payment request it sends back. The Verified badge needs paid calls whose answers match the promised output, and nobody can buy a badge.

Endpoint

POST https://api.zfinia.com/x402/v1/container-compose-contract-audit

CategoryImage and media
Provider hostapi.zfinia.com
Networkseip155:8453
Payment schemesexact
Self-reported calls, 30 days1 from 1 payers (the provider's figure, not ours)

Our checks, last 30 days

DayResultHTTPAskedTime
2026-10-04 valid payment request 402$0.13 3628 ms

Example input (from the provider)

{
  "body": {
    "compose": {
      "services": {
        "api": {
          "environment": [
            "DATABASE_URL=${DATABASE_URL}",
            "LOG_LEVEL=info"
          ],
          "healthcheck": {
            "test": [
              "CMD",
              "curl",
              "-f",
              "http://localhost/health"
            ]
          },
          "image": "ghcr.io/example/api@sha256:0000000000000000000000000000000000000000000000000000000000000000",
          "restart": "unless-stopped",
          "volumes": [
            "./config:/etc/api:ro",
            "api-data:/var/lib/api"
          ]
        },
        "db": {
          "cap_add": [
            "SYS_ADMIN"
          ],
          "image": "postgres:16.3",
          "network_mode": "host",
          "privileged": true,
          "volumes": [
            "/var/lib/postgresql:/var/lib/postgresql"
          ]
        },
        "web": {
          "depends_on": [
            "api",
            "cache"
          ],
          "environment": {
            "API_TOKEN": "not-a-real-token-0123456789abcdef",
            "NGINX_HOST": "example.test"
          },
          "image": "nginx",
          "ports": [
            "80:80",
            "443:443"
          ]
        }
      }
    },
    "contract": {
      "forbid_host_path_mounts": true,
      "required_services": [
        "web",
        "api",
        "cache"
      ]
    }
  },
  "bodyType": "json",
  "method": "POST",
  "type": "http"
}

Promised output schema (from the provider)

{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "properties": {
    "input": {
      "additionalProperties": false,
      "properties": {
        "body": {
          "additionalProperties": false,
          "properties": {
            "compose": {
              "type": "object"
            },
            "contract": {
              "additionalProperties": false,
              "properties": {
                "forbid_host_network": {
                  "type": "boolean"
                },
                "forbid_host_path_mounts": {
                  "type": "boolean"
                },
                "forbid_latest_tag": {
                  "type": "boolean"
                },
                "forbid_privileged": {
                  "type": "boolean"
                },
                "require_healthcheck": {
                  "type": "boolean"
                },
                "require_restart_policy": {
                  "type": "boolean"
                },
                "required_services": {
                  "items": {
                    "maxLength": 128,
                    "type": "string"
                  },
                  "maxItems": 200,
                  "minItems": 1,
                  "type": "array"
                }
              },
              "type": "object"
            }
          },
          "required": [
            "compose"
          ],
          "type": "object"
        },
        "bodyType": {
          "enum": [
            "json",
            "form-data",
            "text"
          ],
          "type": "string"
        },
        "method": {
          "enum": [
            "POST"
          ],
          "type": "string"
        },
        "type": {
          "const": "http",
          "type": "string"
        }
      },
      "required": [
        "type",
        "method",
        "bodyType",
        "body"
      ],
      "type": "object"
    },
    "output": {
      "properties": {
        "example": {
          "type": "object"
        },
        "type": {
          "type": "string"
        }
      },
      "required": [
        "type"
      ],
      "type": "object"
    }
  },
  "required": [
    "input"
  ],
  "type": "object"
}

This page as JSON