Sign inSign up
Node.js

dhi.io/node

Node.js 26.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
alpine 3.23
Tags:

26-alpine3.23-sfw-ent-dev, 26.10-alpine3.23-sfw-ent-dev, 26.10.0-alpine3.23-sfw-ent-dev

Index digest:

sha256:ffa958ec7c194acba8fee23437c0a3ff4279b16679fcef50741e0bcff333cedc

Manifest digest:

sha256:48e68716a08bf560794f7c5e4b3ec8bff882c9ef592f265d23e4f5fe041916df

Size

91.68 MB

Last pushed

20 hours ago

Vulnerabilities

0
4
6
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-alpine3.23-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-alpine3.23-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:d0bd966282ea024fdf587ff70866575559ed882b820e95eb7f65176dfff3fc55
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:389a6d54b729fe5b808b8cf596d0edc1104d08622116cfd96539ffa257813481
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:e1157f39c2c178d819b4c64ce2df8cf8a2d5979081e0fcaec7b835b95dfaf34e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:38ac23630c954c6808c97a5051dd75115d21703c3614f0262870ac40902bbc93
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:0c3d0027157666c7b920d6dd70f711ba8ef8ec9b8b324ac569c7695cf8a47a34
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:5fe7b70e2f36f7227075f96d49df3d99c68bf67798c12f36ed55c08ef3b0f034
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:83b373857241d983dbe2f72a95fcaa9e0dc64c6e8284092ca148011183c04fde
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:3cbb28f283107c974df65732cefe544ac86685ff5621949f126e854eeab154fa
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:aa5db9137ca033035269a99812f08f32d6ce03216e325b72c244f016039885bc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:d9b9840e7910904edd381c2e89550dc55a35718c83d244a9158107a439bcb3cc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:d92ce42a49652de41b8588dfe9123f25409203ce2c6e2dd92aa1db0897063eb1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:1afb39deb570fbaf4ef36c51709cb45f1cb15cfb4f878626e3491d6cbb6a363b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:a5c4ad36518e548231e2ffe649108b28838fbab0ec17834f39211d1f8737d9cb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:2ad76f755979b9e167608880d940f641cf550753d1acc65c9450f623262db7a6