Security-focused Zig dev container with zls integration and a persistent build cache.
| Options Id | Description | Type | Default Value |
|---|---|---|---|
| imageVariant | Zig and Debian version (trixie = Debian 13, bookworm = Debian 12). Other published tags can be entered. | string | 0.16-trixie |
See Getting Started in the repository README for how to apply this template.
The imageVariant option selects the tag of the ghcr.io/bare-devcontainer/zig base image, which pairs a Zig version with a Debian release: trixie is Debian 13 and bookworm is Debian 12.
The values offered when applying the template are proposals, not a closed list — any published tag can be entered, including narrower ones such as a Zig patch version or a dated build for tighter pinning. See the published tags for what is currently available.
This template applies the shared hardening defaults of Bare Dev Container Templates:
- Builds on
ghcr.io/bare-devcontainer/zig, a minimal image from bare-devcontainer/images with pinned digests, SLSA provenance, and an SPDX SBOM for supply-chain transparency. - Runs as the non-root
devuser. - Drops all Linux capabilities (
--cap-drop=ALL) and sets theno-new-privilegessecurity option, so processes cannot gain elevated privileges inside the container. Removeno-new-privilegesfromsecurityOptif you needsu/sudo. - Starts an init process (
"init": true) to reap zombie processes.
After applying the template, we recommend pinning the image to a digest so every rebuild uses exactly the image you expect — see Pinning Images to a Digest.
The Zig global cache is persisted in a named volume, so rebuilding the container to pick up image updates doesn't require re-downloading packages or recompiling dependencies:
| Volume | Mount path | Purpose |
|---|---|---|
${devcontainerId}-zig-global-cache |
/home/dev/.cache/zig |
Zig global cache |
- Installs the
ziglang.vscode-zigVS Code extension, with thezigandzlspaths preconfigured to the binaries shipped in the image and the Zig Language Server (zls) enabled.
- To use the debugger, uncomment
"capAdd": ["SYS_PTRACE"]indevcontainer.json. - If you use VS Code, uncomment the
remoteEnvblock indevcontainer.jsonto open$EDITOR/$VISUAL/$GIT_EDITOR(e.g.git commit) in a VS Code tab.
Note: This file was auto-generated from the devcontainer-template.json. Add additional notes to a NOTES.md.