Secure-by-default JS & TS runtime in Rust. Every capability is denied unless granted.
162
3va is a JavaScript and TypeScript runtime written in Rust with deny-by-default security. It bundles a package manager, process manager, test runner, bundler, and dev server.
| Tag | Description |
|---|---|
latest | Latest release |
v2.9.0 | Pinned release |
Platforms: linux/amd64, linux/arm64. Base: debian:trixie-slim.
The image contains only the 3va binary. Mount your code into /app:
docker run --rm -v "$PWD":/app edge166/3va run app.ts
Filesystem, network, environment variables, child processes, and native addons are all blocked by default. Grant each one explicitly:
docker run --rm -v "$PWD":/app edge166/3va run app.ts \
--allow-net=api.example.com \
--allow-read=/app/data \
--allow-env=DATABASE_URL
A container has no TTY by default, so any capability you don't grant is denied silently. There is no interactive prompt.
docker run --rm -p 3000:3000 -v "$PWD":/app edge166/3va run server.ts --allow-net
docker run --rm -v "$PWD":/app edge166/3va install express --allow-net=registry.npmjs.org
Install scripts (preinstall, postinstall, …) are never executed.
FROM edge166/3va:v2.9.0
COPY --chown=3va:3va . /app
CMD ["run", "app.ts", "--allow-net=api.example.com"]
3va (UID/GID 10001). If you mount a host directory and need to write to it, add --user "$(id -u):$(id -g)"./app3va (the default command is --help)ca-certificates for TLSRelease binaries are signed with Sigstore cosign and ship with SLSA provenance. See SECURITY.md for verification steps.
MIT
Content type
Image
Digest
sha256:7dd2c6e93…
Size
63.4 MB
Last updated
9 days ago
docker pull edge166/3va