Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
alpine 3.23
Tags:

22-alpine3.23-sfw-ent-dev, 22.23-alpine3.23-sfw-ent-dev, 22.23.3-alpine3.23-sfw-ent-dev

Index digest:

sha256:c6a8b0e4a9a7a8eb59bfbe78e9e1c98a272ef7e6f2ee687c5acb254e047eff22

Manifest digest:

sha256:0e01b462267569ba6016187718d05d1d25e1bc59c8df5609cdceffc4cc605092

Size

88.17 MB

Last pushed

17 hours ago

Vulnerabilities

0
3
6
1
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine3.23-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine3.23-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:9cafd7c64e2ab903168ed9577f313902492077a6865955134a25e754018c7087
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:686d64dd57958fd541e3888c60d8b11785c425a6b7f5c726975fa5e7630a7ea3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:3f6f2355122750e89c8ec3a0356159f45cc3ddc1d8e393e34bbf6919efdab6a0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:eb61cecde786be48965844ccd10a1c4e090b6f65d0e23143189ed54c9fa0ff2f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:70309b780d5268d75f959f6be742708ddb92db8bf0e81f4784ac5931bded8e26
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:fe756ca245a8351f00b0ba55b499e66d63e33fb86364dfa65dd033ed456fa82b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:5d4703dabd221f650927b324792b631cf139f894f63c2d30cd791ef8ee650504
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:00229ca225382624bdf4fb50f36c501a2ba3cc874b6dac1b7fb41b1563c83341
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:a96c8df4028ef0718299b9121d1aa4c3b39fef4450911ca3eaa2ae484aa3c174
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:0af1b558343da9d362ef2508b788fcaa26e5fd9e06292e4eb346dc41b5bb7a57
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:c5f79995277c5fdfa05384092957f96a056338f2e194ed13a4dcea36e3f8c624
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:5a836121105c222a38c9868effa126013000a54a5d6389476cc8b0b0a3629666
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:b77ca7f7b1b7dbc2c9e9718c102decbe4d6154f8a631a7e1a4638185b3446f29
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:e0291c113fc9f407b2242b3f56bab9933466c5cd08538d3bb6fbb3f354bcbaca