Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

22-alpine-dev, 22-alpine3.24-dev, 22.23-alpine-dev, 22.23-alpine3.24-dev, 22.23.2-alpine-dev, 22.23.2-alpine3.24-dev

Index digest:

sha256:7f62aaa2b28680210392ca1af02812264c06222ee44bf6e1fc771557dab5930e

Manifest digest:

sha256:3c14b6629384c36d4f1e1ee4803dd6291881a3e84d7719f955577d4bcd650b24

Size

46.41 MB

Last pushed

2 days ago

Vulnerabilities

0
1
0
0
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:580663c98d543744d2ec429bcf7e4a6358ba707a8b971b0a8971d6cf77afd3b6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:8d50411c0f4862eca94a7d35cd788664b0aec8395fb757f531777438722da09c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:0b8987de5e45a04ea1988cc5325891ed4e97536845cef88c8dcbf72adcf2fd2c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:e9d593b587377dd83c0f52f83378f1c219baecd92d9031c43abc38e1c98537a8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:73773a05712029f23821cd3d18850a84ec7df7838c52f6799e560454403accd5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:7da476b0c23ec13dd6f62b973337e6717b3478fda28829eea555a99d6a3292e9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:78435cf0f8acd58aa53baaac101b0d5a2570dfdd2f5c2aa70d317ebc6f20d989
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:5ce7dc12814b90925affbf5692688d1768fd5b3f33e4b71a017e733a2c54ae4a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:9067e05391aaa340327a2c04b5b20bf5599ca663671c07e319b280df103bcecd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:5693d6768b8dfdc2ed5e31461b32a2e749e1ba193c73368d210bbc9af5f02d72
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:75a01adbd1a0b96bb703db55a64eadd88da37e6a10be3bd0c80be4787a316a5c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:e769d846f612256c509ec0bd31f2ec22f10aff816e4fa9649f70ffd45e3d6073
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:eae8a2b0643d25c64718a9cfd31cd3dd980d2abc111d063fa01b36342213c379
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:e12fbcff148e91c00130a80f33dc64c8761f9f0d39988442a68f2f86c77fd771
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:59dea1e4c9148265a8a0611a8de2a56c686d3104c87fe8b917f0ca7a1506eb14