Sign inSign up

baredevcontainer/bun

By baredevcontainer

•Updated 4 days ago

Minimal Dev Container image with Bun: Debian, verified upstreams, SLSA provenance

Image
Security
Languages & frameworks
Developer tools
0

10K+

baredevcontainer/bun repository overview

⁠bun

Mirror. This Docker Hub repository mirrors ghcr.io/bare-devcontainer/bun, under the same tags and with the same digests. GitHub Container Registry receives every build first and applies no pull rate limit, so prefer ghcr.io/bare-devcontainer/bun unless your environment requires Docker Hub, where the image is docker.io/baredevcontainer/bun.

This page is rendered from the image's README in bare-devcontainer/images⁠. That is the repository "this repository" refers to below.

Dev container image for JavaScript/TypeScript development, with the Bun⁠ runtime installed, built on the debian⁠ base image.

Like every image in this repository, it is minimal, built only from upstreams verified at build time, and published with SLSA provenance, a GitHub artifact attestation, and an SBOM; it runs as the non-root user dev. Why these images⁠ explains the reasoning, and Verifying the image⁠ below shows how to check a build.

⁠Image

ghcr.io/bare-devcontainer/bun:<tag>

Reference it from .devcontainer/devcontainer.json, pinning the digest as well as the tag:

{
  "image": "ghcr.io/bare-devcontainer/bun:1@sha256:<digest>"
}

⁠Dev Container Template

A ready-to-use Dev Container template for this image is available at bare-devcontainer/templates⁠. It provides the recommended configuration for this image, including security hardening and volume mounts that persist cache directories for faster rebuilds.

⁠Tags

TagsDebian variant
1.4.2-trixie, 1-trixie, 1.4.2, 1, trixietrixie
1.4.2-bookworm, 1-bookworm, bookwormbookworm

Tags are also published with a date suffix on each build (e.g., 1.4.2-trixie-<YYYYMMDD>).

⁠Installed software

Everything from the debian⁠ base image, plus:

⁠Not installed

  • No Node.js, npm, or npx. Bun runs the scripts and installs the packages. A project that also needs the Node.js runtime is better served by the node⁠ image.
  • No global JavaScript tooling. Linters, formatters, and test runners are left to the project's own dependencies; Bun's built-in test runner and bundler cover part of that ground.

⁠Supply chain

bun is downloaded directly from GitHub Releases⁠. Its checksum is verified against SHASUMS256.txt, whose GPG signature (SHASUMS256.txt.asc) is verified against Bun's release signing key before installation. The key (bun/bun-signing-key.asc) is committed to this repository, so signatures are checked against a key reviewed here rather than one fetched at build time.

⁠Verifying the image

Every build is published with SLSA provenance, a GitHub artifact attestation, and an SBOM. The attestation confirms that an image was built by the release workflow of this repository and has not been altered since:

gh attestation verify oci://ghcr.io/bare-devcontainer/bun:<tag>@sha256:<digest> \
  --owner bare-devcontainer

The Docker Hub mirror carries the same digests, so the same command verifies an image pulled from docker.io/baredevcontainer/bun. Verifying Published Images⁠ covers inspecting the provenance and the SBOM as well.

Tag summary

Content type

Image

Digest

sha256:bc9e3e9c0…

Size

305.6 MB

Last updated

4 days ago

docker pull baredevcontainer/bun:1.4.2-trixie-20260923