Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

22-alpine-dev, 22-alpine3.24-dev, 22.23-alpine-dev, 22.23-alpine3.24-dev, 22.23.3-alpine-dev, 22.23.3-alpine3.24-dev

Index digest:

sha256:89173efd905a8ab773db9d09809313e81507af22788152680dc475122850f859

Manifest digest:

sha256:b2895e68cf90e74b4b859a14448f6b34c1973e998030e82db50eee36c8bbf804

Size

46.41 MB

Last pushed

3 hours ago

Vulnerabilities

0
4
6
1
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:069597c49c5a09470c11268a798094388938b80801ae7755bdc937980556711c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:b711231eb2294b3c07fc1826e7984858e60259a80a35debfd2202cfde1bbd3e1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:3278a35da7cf55f3b7044f7022801f1638e367b927025f7b39fc37fdff0052d8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:845bb593d33229b35b05461bc2d0f5a5957894372e47d728e2982317bfb332b4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:af8433cb3156520835c3cc13a0572edde9a070f8c5f300e1f2f626ae972831dd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:94fc83637d0066c94885aef4bccebdd7ea2f1be590b012f1dd0949b14abce260
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:8ea2a743c2da6f1629f963d1fcc5791d6eb7fd698d35107a64000deaa1416096
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:b8573d155f1d14b43b18b91713309fc4442f3d119decf0fa1349279365aca970
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:a79098f4df0fe50e5f80354071dc6f7fe3377c0a68bb18ab1a2460376d678344
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:ddfbc5117b4f99bc15f14b565f76c33cfd4f5abf1ce5a9bf885c50d161da9248
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:833191b659c1baf655e1ca4248fb05aa0d190d22a94d14b3ce32eabcb4136acf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:9729fbbb89173d9b820b660c8b64302356dd1deeecf9028debc986b1cc82b540
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:c8dbe24bed65be325886dc19bcbe44e60898d48339cd4849cceaa6abd3b67ac0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:185f578195a8908d61dc318a81f999f2a49b961e23a048aa7e9e201b4a0f9a97