Sign inSign up

detoxd/python

By detoxd

•Updated 6 months ago

Image
0

2.4K

detoxd/python repository overview

⁠Python - Detoxd Hardened Image

⁠Overview

Python is a versatile, high-level programming language known for its readability and extensive library ecosystem. Created by Guido van Rossum in 1991, Python has become one of the most popular programming languages in the world, used in web development, data science, AI/ML, automation, and scientific computing.

⁠Common Use Cases

  • Web Development - Django, Flask, FastAPI
  • Data Science - Pandas, NumPy, Jupyter
  • Machine Learning - TensorFlow, PyTorch, scikit-learn
  • Automation - DevOps, scripting, testing
  • API Development - REST and GraphQL backends
  • Scientific Computing - Research and simulations

⁠Security Concerns

Python applications face several security risks:

  • Dependency Vulnerabilities - PyPI packages with security issues
  • Pickle Deserialization - Arbitrary code execution
  • Command Injection - Unsafe subprocess and os.system usage
  • Path Traversal - Improper path handling
  • SSTI - Server-Side Template Injection
  • SQL Injection - Raw SQL queries

⁠What Detoxd Does

⁠pip Package Updates
  • Upgrades pip to latest version
  • Upgrades setuptools and wheel
  • Upgrades commonly vulnerable packages:
    • certifi - Root certificates
    • urllib3 - HTTP library
    • requests - HTTP client
    • cryptography - Cryptographic primitives
    • PyNaCl - Networking and cryptography
    • idna - Internationalized domain names
    • charset-normalizer - Character encoding
    • packaging - Core packaging utilities
⁠System Hardening
  • Updates all Debian packages
  • Removes unnecessary packages
  • Cleans pip and system caches
  • Creates non-root user
⁠Production Configuration
  • Sets PYTHONUNBUFFERED=1 for proper logging
  • Sets PYTHONDONTWRITEBYTECODE=1 to prevent .pyc files
⁠Dockerfile Best Practices
FROM detoxd/python:3.13-slim-detox.1

# Create app directory
WORKDIR /app

# Copy requirements first
COPY requirements.txt .

# Install dependencies
RUN pip install --no-cache-dir -r requirements.txt

# Copy application
COPY --chown=pythonuser:pythonuser . .

# Run as non-root
USER pythonuser

# Use gunicorn for production
CMD ["gunicorn", "-w", "4", "-b", "0.0.0.0:8000", "app:app"]
⁠requirements.txt Pinning
# Pin exact versions
Django==5.0.1
requests==2.31.0
cryptography==42.0.1

# Use hashes for verification
Flask==3.0.0 --hash=sha256:...
⁠Security Tools
# Audit dependencies
pip-audit

# Check for known vulnerabilities
safety check

# Static security analysis
bandit -r ./src

# Dependency scanning
pip-audit --require-hashes
⁠Secure Coding Practices
import subprocess
import os
from pathlib import Path

# BAD: Command injection
# os.system(f"ls {user_input}")

# GOOD: Safe subprocess usage
subprocess.run(["ls", path], capture_output=True, check=True)

# BAD: Path traversal
# open(f"/data/{filename}")

# GOOD: Safe path handling
safe_path = Path("/data").resolve() / filename
if safe_path.is_relative_to(Path("/data").resolve()):
    open(safe_path)

# BAD: Pickle deserialization
# pickle.loads(untrusted_data)

# GOOD: Use JSON or validated formats
import json
data = json.loads(trusted_json_string)
⁠pip.conf Security
[global]
timeout = 60
index-url = https://pypi.org/simple
trusted-host = pypi.org

[install]
no-cache-dir = true
compile = false

⁠Environment Variables

PYTHONUNBUFFERED=1
PYTHONDONTWRITEBYTECODE=1
PIP_NO_CACHE_DIR=1
PIP_DISABLE_PIP_VERSION_CHECK=1

⁠References

Tag summary

Content type

Image

Digest

sha256:1fb7e6035…

Size

46.7 MB

Last updated

6 months ago

docker pull detoxd/python:3.14.3-slim-detox.1