Sign inSign up
Node.js

dhi.io/node

Node.js 26.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

26-alpine3.23-fips, 26.11-alpine3.23-fips, 26.11.1-alpine3.23-fips

Index digest:

sha256:d915ce7ed3fba75bd3cae546e1d29a30aa9149a042d384ed14709c62bba843e4

Manifest digest:

sha256:4cbdb5ac1b628f5b39d430b4e10cc00194c9eafeac85e9429e94a9acb06ca9d7

Size

42.30 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:d34f4abb120d47a61c4e066ca3246fa61835dd92ae6547975bc135343f61c338
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:8d5e0413436d4af9532ac52d5e37ba0846b262878c89ffc332df4ef260b78bc3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:3b65b99a3aa3f3077ba49805fb49fa2a556b0a151aa00387215c4d75c0bfec2f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:95eecee00ee02795ac5a800953f548549db11d67a7878f2afec50e0fbd92a313
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:df2fab425f84db7267a95e5ccb5c8d7b3cd4dbd39540c3a7a86d4b438325ebf0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:13d6911efa807a1d431cd1100c21fa240e739b683acc74d65f3bcbfd093a723e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:69b012f68267918db96e164cfcc1e89be73816aa0516c55d89e53aabdc0e88fc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:1186c01239e4df6eb1920706c63ffded42b8a1b7c14f0e707b8189a7daf74a5e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:6b9b23147952e585241e8d572f01aead7c808d1907d1a4ad7caeccf50f7105eb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:294d7ab172d3dadaa313eec1d2bd9d95c22ae934220838cdee742e67d445af7b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:277c76a3c582d6526aaad695a397f6a7c48da3c71219f105b04ae675401713f5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:eb39a343f16a6643857c1385146836f609d083a030df1656cde016df8c89ae0a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:abbc43479da035ede003898a087b4df8c90dc9ae71a078a33932031c5cd58908
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:7651ba3e49968b6f877e3a17c78e29a755ad9b07a314c27baa630ab8afc7bc1d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:38c87dd0bdf0be59da59504e86c211d71c68fa025a421bfecc227952da1562ae
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:5e061e925f9ce99b4d9d5757252fe31d3f2e48220e11127023e9678423994e93