Blog

Jon Clausen

October 31, 2017

Spread the word


Share your thoughts

CommandBox 3.8 Docker image released



Today we released our 3.8 series of docker images ( current source version 2.1.0 ) which include a number of improvements and enhancements.

Change Log

  • Updates to CommandBox v3.8+
  • Adds support for Docker secrets
  • Adds casing aliases for environment variables
  • Adds new opinionated password security
  • Updates to runtime output for clarity
  • Changes image for alpine build to prevent CommandBox errors when installing dependencies

Security Enhancements

Upon container start, if no mechanism is detected for specifying the administrative passwords for the CFML engine (i.e. - CFConfig, custom server home, or environment variables ), a random password is generated. This prevents the image from using a predictable default. This password is available in the console output like so:

WARN: Configuration did not detect any known mechanisms for changing the default password.  Your CF engine administrative password has been set to: VxnrV816IFaHG0CmNemO251tihWeHZGwcLUJBurzj75y9vRwT7EqdFed9cWu2fIRvUn0pWVIINmoa34g

Docker Secrets

The image now provides support for secrets expansion when using Docker secrets in your singular, swarm, or stack deployment.

To employ the use of secrets in your runtime environment, you may map environment variables to secrets using the following syntax: MYVAR={{DOCKER-SECRET:docker_secret_name}} . Upon container start any environment variables containing these placeholders will expand the secrets and derive their values from the contents of the secret file.

Enjoy and happy coding!

Add Your Comment

Recent Entries

BoxLang 1.17 Series Part 4 : WriteDump Enhanced!

BoxLang 1.17 Series Part 4 : WriteDump Enhanced!

You call writeDump() on an ORM entity or a very rich class graph . The browser locks up. Thirty seconds later you get a page with forty thousand rows on it, you scroll for a while, you give up, and you go edit your code to dump a sub-key instead. Or worse, you crash the server.

Luis Majano
Luis Majano
September 11, 2026
BoxLang AI 3.4 Blog Series Part 4 : Locking Down Prompt Injection

BoxLang AI 3.4 Blog Series Part 4 : Locking Down Prompt Injection

LLM applications face a class of attack traditional input validation was never built for: prompt injection. An attacker embeds instructions in user input, a retrieved document, a web page your tool fetched, or an MCP result, trying to override your system prompt, exfiltrate data, or hijack a tool call. BoxLang AI 3.4.0 ships four layered, configurable defenses against exactly this, plus one more that's on unconditionally.

Luis Majano
Luis Majano
September 11, 2026