Sign inSign up
Node.js

dhi.io/node

Node.js 26.x

CIS
linux/amd64
alpine 3.23
Tags:

26-alpine3.23, 26.10-alpine3.23, 26.10.0-alpine3.23

Index digest:

sha256:1ee7ff96e3e36681d33faaa499174f9daa59bae0d70f6a6a6d23ebd29e1a7b79

Manifest digest:

sha256:44aa4f59d4ba69f4d74a9e30e4afbfe71bb4595ca05696fb51169442d74ccb72

Size

39.11 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:b66c6e6b1b4c05202e26164a93a20df0d4911571138857e7db6403f74eef5f50
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:b25ca6ad9bee302a2b5052e0d00a921db840546801215676db967523f24fb606
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:f5b453d7f91f00c70a332f44207e5672087b1b9b102e0563f771af3175dae9e2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:bf0114e6b583c685c3beea9fa2cb9a5d0e5ff381c492e6fc5daebf979d12e967
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:230584d310a4a035d5701dd9de66950c3f3d19735c55b2b2a8891da4176515f3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:05ae19d474382ef0113a917ea69379d54da7265882abc5c658553f73a88415d6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:88702870985fe58923e29fbf412b11815544d0b393bd11d597f4ef33e6094ae2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:6e1c1ede86a87f5c9ebce36752864279efb75d5aee2f4397550f39869d0c9fa0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:035ea3016661944e1bb118e24c1f13de9ea56d72fd53ee41f3b40eddae76c79e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:863d18fc7f421b2bb545c55096ac6b42e3441b141d6eb751c23d1ed038e16c6e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:a39cfb73306c3e91d9f01c2984440fda501742b7fede4a0ee79f75844b31cb40
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:fae89abc5773fd9f346bd2e313a98523fe3ef861eac212086bc6ecd0e5a1cb20
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:10183e47b0ef0b01d881e8086165b6d9c9fcf3916c81d518f854ec7349610984
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:ca9cb485033df1c9391078a19cd4c402450ac07ee7817a852453d27e1e6f532c