Sign inSign up
Node.js

dhi.io/node

Node.js 26.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

26-alpine3.23-fips, 26.10-alpine3.23-fips, 26.10.0-alpine3.23-fips

Index digest:

sha256:9011e37e9aaccaa53582eaa08df43640062711819693aa4afade15382478351c

Manifest digest:

sha256:244619189bdd5f9a80cab5386413f7aa0e61c585817dcb889d8b96f9ebf45c6a

Size

42.17 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:0720f7e14d510111a318fe74daba8c283cb9e58f241d03efb2605dee53abe506
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:ce037bf01d21458c23129342425b608f9a3e91ceb4515d620d37e196338936bc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:a61cf52965ca3694a6f107632a8c86e7a91c1e6b259da1ef9ec729eb85d007d8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:920681aa99b721ff863888024f5a3ebd39506d7158bfa1301b1d78f058754216
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:64f0847c0a327e9ed63ab474ce4e60775a7b6a132d769c759954863191bdc489
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:37e15f5a47161c5f48da5ee1c05287c6d9a0f74ebd648c28362f268532fee046
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:c01ffc2ace20d3bfd8d9f22c14593ee3da136418667d0de237ff057af2ad9ebf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:067fe1d40bc3eb51cc9adf63fc33dc6306c997c713e864aca86b40591818845b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:af767f3fef3f392cc67e11add58a840fc71e0502ece8a36c0dad23404dce8ed1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:577eaf94b987fc11d5d273ca7f56bf29c8d84dcbfb113e3483be1eb6274d4eb8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:391d6f65c9eeaf8693dd691ccd6761f8fdab58a2efc44ab2d8593445a023a8c0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:9e66f9f2f133fb0c6143659c4d8dc3922f16df5eb068c5f37c65f86baa0d77c0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:d678b88e9722ce801be7fac7d93f1fb86570cbdacb079d2f19cae53213d9312d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:649e7693de633da723e694d29c080001e61af166f558b071bce1c3ed06c6769f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:0fd87e2cb8a05db40b4fabaac1f4583a96713e1dea783c0aafe08a5cc5afb3cf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:37f46e2df3fc968dd7639dc318aa5a850a4667560ce46556e39f418fd308c2cf