Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

22-alpine-dev, 22-alpine3.24-dev, 22.23-alpine-dev, 22.23-alpine3.24-dev, 22.23.3-alpine-dev, 22.23.3-alpine3.24-dev

Index digest:

sha256:288739d87999d0644c7286440df9a626f0e561a229b7053bfe7465bb8333f2f9

Manifest digest:

sha256:ae0deebc38f880ff22fe600c97a1d22297b2876d5bab379360b5045c0e546cd5

Size

46.41 MB

Last pushed

22 hours ago

Vulnerabilities

0
4
6
1
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:477c53b2e46827835eb1b4a7102d7e2ccd836f4ba66b347d5c10074b95432f4b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:94ccc465091e3a565743fb427438bae1ba033eb160a0b12a3d68bf42e5d5d641
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:935ae2f09e897eed97819ee550341a8e51790ad1d03550d2495fce39cfde2953
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:db941fec172c5fa713167107e07d4847481bbf5f8f96b3885af2d387439f889c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:1fa8b798283d77407ff89ca5914228a739f3908d45842153a0a17a4e59f82be7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:c1c0c5b865b7a21405dbde8607bfb5c23b30cb590cfadb9470e7d3f475ec9040
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:257314a7df8917370f8bf953d1ad7bb2ba45efcd9213f7429ac4af463c097ce4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:d17669d2ffacaab20469f79ab49af8df2b5fe7849fab16296e216227ecc0530a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:0129bcda75808613c85707f948163b6b26db67e818977af46220ca06e7601d26
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:f5d74d4b58b32bbe854737b2eda6a91f5514bfddd56e63b0b67a7e14aa996dff
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:9720cdd57ca7b7b8caa93a27ba5ae0f192aa3f5898717bc907803ad7bcf1eb4e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:6d1512f233e96360f80e1a1cdf2f680f0c5a7050e0af249e51b1528a30adae6d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:373ce3cd2a7defd0b6a292b2712570d7a2273660ff03607dea92c0131ee1eb86
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:21b4c1686cc54a10a1fc90e1767586fd90b643372f058665d213d7f517bb96a8