Repository: github.com/detoxd/detoxd | Images: images/python
Python is a versatile, high-level programming language known for its readability and extensive library ecosystem. Created by Guido van Rossum in 1991, Python has become one of the most popular programming languages in the world, used in web development, data science, AI/ML, automation, and scientific computing.
Python applications face several security risks:
certifi - Root certificatesurllib3 - HTTP libraryrequests - HTTP clientcryptography - Cryptographic primitivesPyNaCl - Networking and cryptographyidna - Internationalized domain namescharset-normalizer - Character encodingpackaging - Core packaging utilitiesPYTHONUNBUFFERED=1 for proper loggingPYTHONDONTWRITEBYTECODE=1 to prevent .pyc filesFROM detoxd/python:3.13-slim-detox.1
# Create app directory
WORKDIR /app
# Copy requirements first
COPY requirements.txt .
# Install dependencies
RUN pip install --no-cache-dir -r requirements.txt
# Copy application
COPY --chown=pythonuser:pythonuser . .
# Run as non-root
USER pythonuser
# Use gunicorn for production
CMD ["gunicorn", "-w", "4", "-b", "0.0.0.0:8000", "app:app"]
# Pin exact versions
Django==5.0.1
requests==2.31.0
cryptography==42.0.1
# Use hashes for verification
Flask==3.0.0 --hash=sha256:...
# Audit dependencies
pip-audit
# Check for known vulnerabilities
safety check
# Static security analysis
bandit -r ./src
# Dependency scanning
pip-audit --require-hashes
import subprocess
import os
from pathlib import Path
# BAD: Command injection
# os.system(f"ls {user_input}")
# GOOD: Safe subprocess usage
subprocess.run(["ls", path], capture_output=True, check=True)
# BAD: Path traversal
# open(f"/data/{filename}")
# GOOD: Safe path handling
safe_path = Path("/data").resolve() / filename
if safe_path.is_relative_to(Path("/data").resolve()):
open(safe_path)
# BAD: Pickle deserialization
# pickle.loads(untrusted_data)
# GOOD: Use JSON or validated formats
import json
data = json.loads(trusted_json_string)
[global]
timeout = 60
index-url = https://pypi.org/simple
trusted-host = pypi.org
[install]
no-cache-dir = true
compile = false
PYTHONUNBUFFERED=1
PYTHONDONTWRITEBYTECODE=1
PIP_NO_CACHE_DIR=1
PIP_DISABLE_PIP_VERSION_CHECK=1
Content type
Image
Digest
sha256:1fb7e6035…
Size
46.7 MB
Last updated
6 months ago
docker pull detoxd/python:3.14.3-slim-detox.1