Skip to content

Latest commit

 

History

History
58 lines (35 loc) · 3 KB

File metadata and controls

58 lines (35 loc) · 3 KB

Node.js (node)

Security-focused Node.js dev container for JS/TS with non-root defaults and Corepack.

Options

Options Id Description Type Default Value
imageVariant Node.js and Debian version (trixie = Debian 13, bookworm = Debian 12). Other published tags can be entered. string 26-trixie

Getting Started

See Getting Started in the repository README for how to apply this template.

Image Variants

The imageVariant option selects the tag of the ghcr.io/bare-devcontainer/node base image, which pairs a Node.js version with a Debian release: trixie is Debian 13 and bookworm is Debian 12.

The values offered when applying the template are proposals, not a closed list — any published tag can be entered, including narrower ones such as a Node.js patch version or a dated build for tighter pinning. See the published tags for what is currently available.

Security Hardening

This template applies the shared hardening defaults of Bare Dev Container Templates:

  • Builds on ghcr.io/bare-devcontainer/node, a minimal image from bare-devcontainer/images with pinned digests, SLSA provenance, and an SPDX SBOM for supply-chain transparency.
  • Runs as the non-root dev user.
  • Drops all Linux capabilities (--cap-drop=ALL) and sets the no-new-privileges security option, so processes cannot gain elevated privileges inside the container. Remove no-new-privileges from securityOpt if you need su/sudo.
  • Starts an init process ("init": true) to reap zombie processes.

After applying the template, we recommend pinning the image to a digest so every rebuild uses exactly the image you expect — see Pinning Images to a Digest.

Persistent Caches

Corepack's cache directory is persisted in a named volume, so rebuilding the container to pick up image updates doesn't require re-downloading package managers:

Volume Mount path Purpose
${devcontainerId}-node-corepack-cache /home/dev/.cache/node/corepack Corepack's cache of downloaded yarn/pnpm releases

Tips

  • npm and npx are not shipped in the image. If you enable npm through Corepack, keep npm's download cache across container rebuilds by adding a named volume to mounts in devcontainer.json:

    {
      "source": "${devcontainerId}-npm-cache",
      "target": "/home/dev/.npm",
      "type": "volume"
    }
  • If you use VS Code, uncomment the remoteEnv block in devcontainer.json to open $EDITOR/$VISUAL/$GIT_EDITOR (e.g. git commit) in a VS Code tab.


Note: This file was auto-generated from the devcontainer-template.json. Add additional notes to a NOTES.md.