Lightweight Docker images for aube — a fast, security-first Node.js package manager — bundled with Node.js.
Built for one job: building/installing JS apps in Docker and CI. There is no npm, npx, corepack or yarn in these images; aube replaces them. It reads and writes package-lock.json, yarn.lock and pnpm-lock.yaml in place, so it drops into existing projects without lockfile migration.
| Registry | Image |
|---|---|
| GHCR | ghcr.io/shadowarcanist/aube |
| Docker Hub | docker.io/shadowarcanist/aube |
All images are multi-arch (linux/amd64, linux/arm64). <version> below is the aube release, e.g. 1.35.0.
| Variant | Base | Size (uncompressed) | Tags |
|---|---|---|---|
| alpine (default) | Alpine 3.22 (musl) | ~254MB | latest, alpine, <version>, v<version>, <version>-alpine, v<version>-alpine |
| debian | Debian bookworm-slim (glibc) | ~377MB | debian, <version>-debian, v<version>-debian |
Use the debian variant if your app has native dependencies that don't play well with musl (glibc-only prebuilt binaries, sharp/canvas edge cases, etc.). Otherwise the alpine variant is smaller.
- Node.js 24.18.0 (workflow default, overridable per build) copied onto a bare base image — only
ca-certificatesand node's runtime libs are added aubestatic musl binary from official GitHub releases, withaubr(script runner) andaubx(like npx) as symlinks — they are identical multi-call binaries, and the same static binary works in both variants- No npm / npx / corepack / yarn
As a build stage in your app's Dockerfile:
FROM ghcr.io/shadowarcanist/aube:latest AS build
WORKDIR /app
COPY package.json package-lock.json ./
RUN aube install
COPY . .
RUN aubr buildOr directly:
docker run --rm -v "$PWD:/app" ghcr.io/shadowarcanist/aube:latest aube installThe build workflow checks aubepkg/aube releases daily and, when a new version appears, builds both variants natively on amd64 + arm64 runners and publishes multi-arch manifests to GHCR and Docker Hub.
Manual runs (workflow_dispatch) support:
version— build a specific aube release (default: latest)node_version— override the bundled Node.js versionforce_rebuild— rebuild even if the image tag already existsskip_latest_tag— skip the moving tags (latest,alpine,debian) when backfilling old versions
Required repository secrets for Docker Hub publishing: DOCKERHUB_USERNAME, DOCKERHUB_TOKEN. GHCR uses the built-in GITHUB_TOKEN.
docker build -f alpine.Dockerfile --build-arg AUBE_VERSION=v1.35.0 -t aube:alpine .
docker build -f debian.Dockerfile --build-arg AUBE_VERSION=v1.35.0 -t aube:debian .
docker run --rm aube:alpine aube --version