A standard dev container for Haskell software development.
1.5K
A ready-to-use Docker image for Haskell development, built on top of the VS Code Dev Containers base image. Pull it, attach VS Code, and get a fully configured Haskell environment in seconds — no local toolchain required.
// .devcontainer/devcontainer.json
{
"image": "ivelten/haskell-devcontainer:latest",
"remoteUser": "vscode",
"postCreateCommand": "npm install -g @anthropic-ai/claude-code",
"runArgs": [
"--cap-drop=ALL",
"--security-opt=no-new-privileges:true",
"--pids-limit=2048"
]
}
Security note: Never add
"privileged": trueor mount/var/run/docker.sock. Either grants any process inside the container (including AI coding assistants) full control over your host's Docker daemon.
| Tool | Version |
|---|---|
| GHC | 9.10.3 |
| Cabal | 3.12.1.0 |
| Stack | latest |
| GHCup | latest |
.cabal filesbash and zshpostCreateCommandFull Debug Adapter Protocol support via haskell-dap, ghci-dap, and haskell-debug-adapter.
Images are built for linux/amd64 (Intel/AMD) and linux/arm64 (Apple Silicon).
The runArgs in the Quick Start snippet enforce least-privilege:
| Flag | What it prevents |
|---|---|
--cap-drop=ALL | Removes all Linux capabilities |
--security-opt=no-new-privileges:true | Prevents privilege escalation via setuid/setgid |
--pids-limit=2048 | Prevents fork bombs; high enough for parallel GHC compilation |
direnv is compiled from source inside a golang builder stage rather than downloaded as a prebuilt binary, ensuring the embedded stdlib is always the patched version.
Built and published automatically on every version tag (v*.*.*) and manual dispatch via GitHub Actions. Versioned tags follow semver: v1.2.3 publishes :1.2.3, :1.2, :1, and :latest.
The pipeline runs two Trivy gates before publishing: a Dockerfile misconfiguration scan and an image vulnerability scan, blocking the push on any fixable CRITICAL/HIGH CVEs.
Content type
Image
Digest
sha256:7024c8c28…
Size
2.6 GB
Last updated
5 months ago
docker pull ivelten/haskell-devcontainer