ShadowArcanist/aube-docker

Lightweight Docker images for aube — a fast, security-first Node.js package manager

★ 1Forks 0DockerfileGitHub ↗Compare

README

aube-docker

Lightweight Docker images for aube — a fast, security-first Node.js package manager — bundled with Node.js.

Built for one job: building/installing JS apps in Docker and CI. There is no npm, npx, corepack or yarn in these images; aube replaces them. It reads and writes package-lock.json, yarn.lock and pnpm-lock.yaml in place, so it drops into existing projects without lockfile migration.

Images

Registry Image
GHCR ghcr.io/shadowarcanist/aube
Docker Hub docker.io/shadowarcanist/aube

Variants & tags

All images are multi-arch (linux/amd64, linux/arm64). <version> below is the aube release, e.g. 1.35.0.

Variant Base Size (uncompressed) Tags
alpine (default) Alpine 3.22 (musl) ~254MB latest, alpine, <version>, v<version>, <version>-alpine, v<version>-alpine
debian Debian bookworm-slim (glibc) ~377MB debian, <version>-debian, v<version>-debian

Use the debian variant if your app has native dependencies that don't play well with musl (glibc-only prebuilt binaries, sharp/canvas edge cases, etc.). Otherwise the alpine variant is smaller.

What's inside

  • Node.js 24.18.0 (workflow default, overridable per build) copied onto a bare base image — only ca-certificates and node's runtime libs are added
  • aube static musl binary from official GitHub releases, with aubr (script runner) and aubx (like npx) as symlinks — they are identical multi-call binaries, and the same static binary works in both variants
  • No npm / npx / corepack / yarn

Usage

As a build stage in your app's Dockerfile:

FROM ghcr.io/shadowarcanist/aube:latest AS build
WORKDIR /app
COPY package.json package-lock.json ./
RUN aube install
COPY . .
RUN aubr build

Or directly:

docker run --rm -v "$PWD:/app" ghcr.io/shadowarcanist/aube:latest aube install

Automation

The build workflow checks aubepkg/aube releases daily and, when a new version appears, builds both variants natively on amd64 + arm64 runners and publishes multi-arch manifests to GHCR and Docker Hub.

Manual runs (workflow_dispatch) support:

  • version — build a specific aube release (default: latest)
  • node_version — override the bundled Node.js version
  • force_rebuild — rebuild even if the image tag already exists
  • skip_latest_tag — skip the moving tags (latest, alpine, debian) when backfilling old versions

Required repository secrets for Docker Hub publishing: DOCKERHUB_USERNAME, DOCKERHUB_TOKEN. GHCR uses the built-in GITHUB_TOKEN.

Local build

docker build -f alpine.Dockerfile --build-arg AUBE_VERSION=v1.35.0 -t aube:alpine .
docker build -f debian.Dockerfile --build-arg AUBE_VERSION=v1.35.0 -t aube:debian .
docker run --rm aube:alpine aube --version

Contributors

ShadowArcanist

Issues