Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

22-alpine3.23-fips-dev, 22.23-alpine3.23-fips-dev, 22.23.3-alpine3.23-fips-dev

Index digest:

sha256:bb02e8e4f3aff3b0490f1d1c42a15aaf52a948877f0e4a339f8cecce140219c3

Manifest digest:

sha256:5dd16e627b49beb0853b32d2dca00c66f892fc35b0a6cbf5084003cec0eae518

Size

47.64 MB

Last pushed

8 hours ago

Vulnerabilities

0
3
6
1
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:f28bcb16f50142c04b756c5c5c3951869deb38cecf4180da6ac5c30548bdff9e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:8338566ea80d2b54b4e7d8d0f17a2c33beafc8d3f4f3f236f654c5bb0a5cd07c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:76bc488cd7707f2a1243c1da819b949395c0863dc559c55794eeec1ca5832e01
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:8ce25ad908350d5eccc388c6fb258538f6920ac77c60bfe0eceaab041c064ce3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:ea5845753c5049039106d2b7775fbe9c2c496dd24dcff5fdc3b62abf728e1dd0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:7bb734e46dd7ce2f50da9f3a1dad51c1422df56caee793514c8a413d115f6a40
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:4ae1d3993570b5bbc53dca04d479915df9914c5f87955ccd45d45e89e8be159e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:48d11f337b41020aeb1a56c7b71efe5ba37fc9c4bf6bd658755bcc0a2205d43e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:b9fd35deb5b64440290e0d46584421d8c35faa322586d2ed08dcd5a6ac47fdc0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:5bdc01669cc88f78fe529689281abb0e39cfaf877d40bf7a0f54cd1eb61c8f9b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:64cd8da62202460705452712cdb0897e2ff1ae7910967f37d9cdc080be8fa728
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:07657c084fd0722eadccdccf4efeacdca1d3ba246e1ffc18c7beedc0986f76b1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:f43b02063a35a1394f1c927cd9dfea4cbc3da1efb3b17d68b6014d4aa4d96d02
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:07643d3b30d526e8fb594aa1593ee2ea26fb320643e0de12535a9a54cda4f366
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:a180d8f64d0483c8d6c673b203b9a5ed4577480c067d2ec0884c5d5cb0895838
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:6887886c8ad91d1d3783787f39cadd893855f488c7f9356cd23f8d1339c8734d