{"repo":"theredguild/devcontainer","free":true,"listed":false,"github":"https://github.com/theredguild/devcontainer","clone":"git clone https://github.com/theredguild/devcontainer.git","description":"The Red Guild's devcontainer focused in web3 and security.","language":"Dockerfile","stars":112,"topics":["devcontainer","security","security-tools","web3"],"license":null,"category":"blockchain-web3","readme_excerpt":"The Red Guild's devcontainer explorations This repo is always a work in progress. Feel free to suggest improvements or requirements as well. Check out similar projects like @Deivitto 's auditor-docker and @trailofbit's eth-security-toolbox. The most important thing about these devcontainers is that we always try to find the best way to install the most popular tools, so they can all work seamlessly, and at the same time, add security by default. If you want to know more and really want to take advantage of these devcontainers, read below. [!IMPORTANT] Dev Containers can improve your workflow, but they are not a fully secure environment . If you need to run untrusted or suspicious code, use GitHub Codespaces, GitPod, or a similar remote setup — never run it directly on your machine . [!CAUTION] VS Code considerations: VS Code does a lot to improve user experience, but that doesn't come without security tradeoffs. VS Code might allow API calls that can lead to running arbitrary commands on the host machine, and by default, it shares sockets such as the gpg-agent’s, which means keys stored outside the container can be used for signing. This opens the door to blind-signing commits scenarios, where a process inside the container may trigger signatures without the user’s full awareness. If you want to deep dive into these \"tricks\", we're working on an article covering the most relevant of them — stay tuned. Quickstart with GitHub Codespaces You can also run our prebuilt container i","default_branch":null,"files":null,"tree":[],"storefront":"/r/theredguild","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/theredguild/devcontainer/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}