Sign inSign up
Node.js

dhi.io/node

Node.js 26.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

26-alpine3.23-fips-dev, 26.10-alpine3.23-fips-dev, 26.10.0-alpine3.23-fips-dev

Index digest:

sha256:819bb47695f4cbcce23f41a3e4fba34734aa411c20026c3fe8eb8d73a10f985a

Manifest digest:

sha256:54ae59494454ccc601959ee3a9a6340b929f6d7750a4a1ff1ff3b564e184f6fe

Size

51.05 MB

Last pushed

20 hours ago

Vulnerabilities

0
4
6
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:a101a54f505dc330aaa609a29a83ce2c369e7f72e927ffba8574ca5f640a288d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:2d0297729ae865297c53f7e88402bd55f0c792457def2f68d7d26901b62c0d4a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:4f25ad4f4260732fd467a70d41d02288d97cc8d9aef6424e568528a09bbfebd9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:a83a284dd234635267c8800ba4dc243907347736031d3e7f2663d79de76d7974
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:baed07ec31ef2e5f3bba56dc867ac695632bbe8faf71f517dfc3d00a6379d9f3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:0038f35d533e3ab81d9b8e25a44510b2609800e017528d149e394a1130c5e8a2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:9b5735fd6822fbdede7bfab21afb0fc1666b9905854366844fad0416aee95df9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:920d206666e7a4275625aca485ed3bacf9b2e4de72c746c061f7adb848f7e258
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:58748fd60ec18d7d98c8933107ce63ec39e2e58b07e91d2f83e37fa915454099
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:ae2e28fd298488f1263973276d02ff615c3b37b9bfb947dc0e14f24db42e30fc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:4b8a63303c3185d9748e457ca10cb1ef18772653bf6c46cb39523d5aa3ef2d15
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:7dbcd12e8e7b0863cdace9063b2c7064aec53e984581acdef8237a6db7db5816
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:85ae0af14077de2418fbfceb3f722defa8233c139126e9f8fcc13994228c1660
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:6125697040faf78bff676d068f8f81e8d2edf331d42af24fd9d506b6ce59427a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:4bf05da6ab2e5861e3fb43637550d8c39e2b20c2e1c9cac670c9d78d1a5219be
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:4e7de78784c064345c4d2a37b6b7c75e146876b5e47af95000e9a0c4cf855110