Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

22-alpine3.23-fips-dev, 22.23-alpine3.23-fips-dev, 22.23.3-alpine3.23-fips-dev

Index digest:

sha256:603bdb86a3172a66d4d9dbcbb95129fabc915e6e23782e9f46ea14325a301801

Manifest digest:

sha256:ada902801194d0422003ce8663f9e5d0069ebce2ce6dfbaff447d10016a86b48

Size

47.64 MB

Last pushed

1 day ago

Vulnerabilities

0
4
6
1
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:cbee97bd287ad3e8afd8a06ece7a5a0031a9bb1a525e7ce4a71ed5697d61c0a0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:becb4b4d356c9c6ee1a0549dcf4ef4908219f0c9cd333fae527504b5d0bf4942
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:ec8a0bfb77a880abcfcf1be21608d3da806dc6f46c5de618f941b9b9acf53809
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:d68207b9ee53de52234451733b0aeb83c45552d8fa38c56565241aceb48626a4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:fed84a0ca4b0804b5fef7c89e9109b7a014e98a90dacfa173c3b330440f9467d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:85653e629c6c6634225dad1fa6e6c693ed9677b50a48148ee0abc345207268f0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:989a79008b0eb142573171c2a39099693829806444cde0751fa174d2d001b894
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:a783158b4efaa9353772101471d25221c8ff002fa428c393dc5788a47f9ebf2e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:38167e992db3e749306e8534b2f4fd246d650b11d17129f193e1af0c4fb727fb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:5dba9386b06d481a1476d66041e17fd4f3dbc02575c10f8f65777bbcd130f963
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:beba34f8e79ab9e27e5ef1d398f5bf07fca9e496144e8b0d04c9ac87325bb752
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:104c4a8381309d5d33fe98a928b3f7fa9d841de2446d8b744242933b177cfb12
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:253cbbd2154379b26e5848b7b4c7275751363396e0f07bf74746c5c5c567892d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:377620140858303003b83890705037105ac39949fb4caf52054a71c4ce199bbb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:620eca361fe0403b2804b37fa0e00c7ab2042a219f47d7bc6fe8589b7bfc9105
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:b38bd9f61e6a345c0028e001dc18fc9e68258d07f3d1486441bd05c7f360e214