Local, metadata-only boundary

Directory mode reads only browser-provided relative-path and name metadata. It never reads ordinary directory file bytes. Only separately selected .dockerignore and Dockerfile inputs are read, after size checks. On-screen paths remain private input: guard screenshots and shoulder-surfing.

Name signals are conservative review prompts, not content secret detection. This bounded tool does not build, upload, archive, execute, or prove Docker/Moby/BuildKit parity or safety.

Input 1 · required

.dockerignore

UTF-8 · 262,144 bytes

Choosing a file clears paste; entering paste clears the selected file.

Input 2 · optional

Dockerfile

UTF-8 · 262,144 bytes

Optional. Choosing a file clears paste; entering paste clears the selected file.

Input 3 · required

Relative path inventory

10,000 paths · 2,097,152 metadata bytes

F[TAB]relative/path marks a file; D[TAB]relative/path/ marks a directory. An unmarked path has unknown kind, uses conservative matching, and creates a review finding. Interior empty lines are rejected. Choosing a directory clears paste; entering paste clears the directory selection.

Bounded subset, not a build verdict

The ignore matcher supports comments, blank lines, escaped leading markers, slash normalization, *, ?, **, directory descendants, anchored/unanchored rules, negation, and last-match-wins. Unsupported brackets/escapes and trailing whitespace get fixed review findings. The Dockerfile scanner recognizes bounded shell/JSON COPY/ADD, continuations, flags, stages, remote sources, and dynamic sources without executing anything.

It does not resolve symlinks, permissions, build arguments, environments, named contexts, mounts, per-Dockerfile ignore files, platform behavior, archives, image builds, remote content, or full parser semantics. False positives and false negatives are possible.

Optional manual review

Docker build-context privacy/preflight review — USD 19

One path inventory, one .dockerignore, one Dockerfile, up to 10,000 paths, one aggregate report, a remediation checklist, and one revision.

Email winni80@gmail.com. In the first email, do not attach a source archive, .env, key, certificate, token, or raw private path. Send only the aggregate report and your Docker/BuildKit version.

This is an inquiry route only. There is no payment link, and the offer is not evidence of inquiry, demand, payment, or revenue.