Sign inSign up

ivelten/haskell-devcontainer

By ivelten

•Updated 5 months ago

A standard dev container for Haskell software development.

Image
Developer tools
0

1.5K

ivelten/haskell-devcontainer repository overview

⁠haskell-devcontainer

A ready-to-use Docker image for Haskell development, built on top of the VS Code Dev Containers⁠ base image. Pull it, attach VS Code, and get a fully configured Haskell environment in seconds — no local toolchain required.

⁠Quick Start

// .devcontainer/devcontainer.json
{
  "image": "ivelten/haskell-devcontainer:latest",
  "remoteUser": "vscode",
  "postCreateCommand": "npm install -g @anthropic-ai/claude-code",
  "runArgs": [
    "--cap-drop=ALL",
    "--security-opt=no-new-privileges:true",
    "--pids-limit=2048"
  ]
}

Security note: Never add "privileged": true or mount /var/run/docker.sock. Either grants any process inside the container (including AI coding assistants) full control over your host's Docker daemon.

⁠What's Inside

⁠Haskell Toolchain
ToolVersion
GHC9.10.3
Cabal3.12.1.0
Stacklatest
GHCuplatest
⁠Developer Tools
  • HLS⁠ — Haskell Language Server (completions, type hints, go-to-definition)
  • Hoogle⁠ — Local Haskell API search, pre-generated at build time
  • Ormolu⁠ — Opinionated, deterministic code formatter
  • fast-tags⁠ — Fast tag file generator for Haskell source
  • cabal-gild⁠ — Formatter and linter for .cabal files
  • direnv⁠ — Per-directory environment variables, hooked into bash and zsh
  • Node.js & npm — Available for installing npm-based tools via postCreateCommand
⁠Debugging (DAP)

Full Debug Adapter Protocol⁠ support via haskell-dap, ghci-dap, and haskell-debug-adapter.

⁠Platform Support

Images are built for linux/amd64 (Intel/AMD) and linux/arm64 (Apple Silicon).

⁠Security

The runArgs in the Quick Start snippet enforce least-privilege:

FlagWhat it prevents
--cap-drop=ALLRemoves all Linux capabilities
--security-opt=no-new-privileges:truePrevents privilege escalation via setuid/setgid
--pids-limit=2048Prevents fork bombs; high enough for parallel GHC compilation

direnv is compiled from source inside a golang builder stage rather than downloaded as a prebuilt binary, ensuring the embedded stdlib is always the patched version.

⁠CI/CD

Built and published automatically on every version tag (v*.*.*) and manual dispatch via GitHub Actions. Versioned tags follow semver: v1.2.3 publishes :1.2.3, :1.2, :1, and :latest.

The pipeline runs two Trivy gates before publishing: a Dockerfile misconfiguration scan and an image vulnerability scan, blocking the push on any fixable CRITICAL/HIGH CVEs.

⁠Source

github.com/ivelten/haskell-devcontainer⁠

Tag summary

Content type

Image

Digest

sha256:7024c8c28…

Size

2.6 GB

Last updated

5 months ago

docker pull ivelten/haskell-devcontainer