Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
alpine 3.23
Tags:

22-alpine3.23-sfw-ent-dev, 22.23-alpine3.23-sfw-ent-dev, 22.23.3-alpine3.23-sfw-ent-dev

Index digest:

sha256:5de23f61bc55d5e41e8d6f642cdfb4b0ceae739e3e0d3a3120fa6c0bddea36b4

Manifest digest:

sha256:306334eb121ec0d397ac1e34951556fd717ff64289874a8a1c0a8aeaeadada39

Size

88.22 MB

Last pushed

3 hours ago

Vulnerabilities

0
4
6
1
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine3.23-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine3.23-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:adf0994fb3f3c03dea87752f5b5bb398e09ab6ac49e8e19fc712a7466ccbe3d0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:8e91cacff4a22db252977e95b8ab06dc7e4f485a0965332edbd49261a1f7069e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:58ce1c38c203a526a12dd495db90a3720aa354a07722fefbe1d14df2f70fbdac
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:45e18dbd81607d812d6ad50c4b899b50170b43951532d84d8428fe153d00d8a4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:e6e4a44a43788e319c349fa82df04ae5aa362e33739f71a053045a0cbae88f40
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:ce4fe9ca607cc3ce6e697182b0b18b039f59c8662c80d7e6967d1892d168ecec
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:bc4d03c54b20065278770292e911521c540e1d2fb9008638e353878c9359b0a7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:e4d7278cc340e7a68782b834eaeb5008a4d390735e1eb3fc783f7ca30688ba59
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:9f677a3b5bd95a31dfa0f6b1c620f3a2bce07244633c21f2ceebfc5cd2cae966
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:0b4223e5d69cbb795c61ba0018bb1899ae9bf176740656b0e4ad9a489cb84fa3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:3e2ac6ad7ed07448c8f285fc561d3c1e490a87f1ada49e931ad473c0cdd6a942
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:20c925578c0f97ff6031c1a090a63bf4d7834567021947f51e8f0d5b360a4970
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:fc9b40b7975a27316694a697b0bdd026146d784a01e622153c8236cc896208a3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:9eec4ee2d711dff94108ee61bb21174d8096f5e610bf98275228bfa75702a929