Dockerfile-level inspection
The scanner reads the pasted Dockerfile as build instructions and reports concerns associated with directives and literal values, including FROM, USER, HEALTHCHECK, and places where credentials may be embedded. It performs this review in the browser, so the Dockerfile is not uploaded. It does not need a built image to identify these source-level signals.