Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
alpine 3.23
Tags:

22-alpine3.23-sfw-dev, 22.23-alpine3.23-sfw-dev, 22.23.3-alpine3.23-sfw-dev

Index digest:

sha256:7c4639b713d81c8a5f8f9672484a7d231794695b264605fedc27f12ea76b93b6

Manifest digest:

sha256:3fa80b8d7145c6bdf148b3bcf13ca0d58aff6fd5d26fce68e9b35a7f13ce9bab

Size

84.64 MB

Last pushed

7 hours ago

Vulnerabilities

0
4
6
1
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine3.23-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine3.23-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:796fc4886d992265a3b53cb80e8ce831a90e7971f86f32b797131300a0e6ecb0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:c3cd783044860bda17b245613456e0bfa0ee396126dafd32d4740f80e98daab3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:2c74c2428149ad08a1a9b394ab9f6106ff14b2f69d71303d8cf92711ce5a4c8a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:efb5535acc9e6d3865ff1cd5f2e6a0a4c185a35f6ff3f32d643a055f5de76ad0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:5c5e7850edf81b92d4e4e37a91e2b3376c642424aba48dc068c69bd4a7caaa9a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:046ea1f702ede193e33e380a251285ee85a72d8aecea7c83c2a5e114793750f9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:093b73e15b6fc551bbea053cd156b14fd8fd2ae0f7bbd0206eb36c84b7813963
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:5e19ebf9cdf0dd1c48eec27253ab1b2cca0afa8d4af4c002333e5974134c6098
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:f9de5978aeed3e6298dffe7c17d5cebf2e3bd645ab04a1cb01dfa7fb51bf2694
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:799365cc69b6fd4f1f05f7cbc7f732d52b1855e000b47745422a659ddac24d00
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:db876fa136395397d583f0308a48f0a5ee2c1e5ce7a2858170429ac10c406fee
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:9306034d31f60fb8e0db188f1840b5f5ccacc4a034bd464b583badeb441c2638
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:db5903f2f2422c54424a79eb3b0c480b04ef57387467fa827242e777e351a781
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:73d1c946d17820cafd8e59004c41be3695649a949c2084184589fa1fd692ff44