Sign inSign up

detoxd/node

By detoxd

•Updated 6 months ago

Image
0

1.2K

detoxd/node repository overview

⁠Node.js - Detoxd Hardened Image

⁠Overview

Node.js is a JavaScript runtime built on Chrome's V8 JavaScript engine. Created by Ryan Dahl in 2009, it enables JavaScript to run server-side, making it possible to build scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient.

⁠Common Use Cases

  • Web Servers - Express.js, Fastify, Koa
  • REST APIs - Backend services for web and mobile apps
  • Real-time Applications - Chat, gaming, collaboration tools
  • Microservices - Lightweight containerized services
  • CLI Tools - npm packages and development tools
  • Serverless Functions - AWS Lambda, Azure Functions

⁠Security Concerns

Node.js applications face unique security challenges:

  • Dependency Vulnerabilities - Thousands of npm packages with varied security
  • Prototype Pollution - JavaScript-specific attack vector
  • Command Injection - Unsafe child_process usage
  • Path Traversal - Improper file path handling
  • ReDoS - Regular expression denial of service
  • Server-Side JavaScript Injection - eval() and similar dangers

⁠What Detoxd Does

⁠npm Updates
  • Updates npm to latest version
  • Cleans npm cache
  • Removes cached packages
⁠System Hardening
  • Updates all Alpine packages to latest versions
  • Removes unnecessary packages and tools
  • Removes setuid/setgid bits from binaries
  • Creates non-root user for running applications
⁠Production Configuration
  • Sets NODE_ENV=production
  • Removes development artifacts
  • Minimal attack surface
⁠Dockerfile Best Practices
FROM detoxd/node:22-alpine-detox.1

# Create app directory
WORKDIR /app

# Copy package files first (for better caching)
COPY package*.json ./

# Install production dependencies only
RUN npm ci --only=production && \
    npm cache clean --force

# Copy application code
COPY --chown=nodeuser:nodeuser . .

# Run as non-root user
USER nodeuser

# Use specific command (not npm start)
CMD ["node", "server.js"]
⁠Security Middleware
const helmet = require('helmet');
const rateLimit = require('express-rate-limit');
const hpp = require('hpp');
const xss = require('xss-clean');

const app = express();

// Security headers
app.use(helmet());

// Rate limiting
app.use(rateLimit({
  windowMs: 15 * 60 * 1000, // 15 minutes
  max: 100 // limit each IP to 100 requests per window
}));

// Prevent parameter pollution
app.use(hpp());

// Prevent XSS attacks
app.use(xss());

// Disable X-Powered-By
app.disable('x-powered-by');
⁠Dependency Security
# Audit dependencies
npm audit

# Fix vulnerabilities automatically
npm audit fix

# Check for outdated packages
npm outdated

# Use lockfile
npm ci  # Instead of npm install
⁠.npmrc Security
# Always use lockfile
package-lock=true

# Audit on install
audit=true

# Ignore scripts from dependencies (optional, may break some packages)
ignore-scripts=true

# Use specific registry
registry=https://registry.npmjs.org/

⁠Environment Variables

NODE_ENV=production
NODE_OPTIONS="--max-old-space-size=256"
NPM_CONFIG_LOGLEVEL=error

⁠References

Tag summary

Content type

Image

Digest

sha256:c8d724913…

Size

54.5 MB

Last updated

6 months ago

docker pull detoxd/node:22.22.2-alpine3.23-detox.1