Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
alpine 3.24
Tags:

22-alpine-sfw-dev, 22-alpine3.24-sfw-dev, 22.23-alpine-sfw-dev, 22.23-alpine3.24-sfw-dev, 22.23.2-alpine-sfw-dev, 22.23.2-alpine3.24-sfw-dev

Index digest:

sha256:f960c3e5a1597801bf0ae7360f6baca00bb13107ee921a660a485292c89dc522

Manifest digest:

sha256:234aab18ee60c9beb0fd7c381ee75f5f71e427c381ab3d3a4a912c5bd4d344dc

Size

84.09 MB

Last pushed

21 days ago

Vulnerabilities

0
1
0
0
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:9a2af8fcddf04baf5bd4a2471c8ca5378762b31f047ef28ac19c1722a1dbc0fc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:f771358ab5ede68bf57072256ebaf9fe75783569ddaf1d1e3d7fc023906be79d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:72bafff1fc06a8273c2ee6134b0cd76e3a3beaed91f7f656e89955d5c291b765
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:ca1b164b3b8abb00f3e55fb60d40d164240cf01be6ed621ac8f897b55b31758c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:d2651f6627306ecdf445022d3501a6809aab7d36e435e39148d969d99a12f3be
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:f095d16bb60e7499f355be2f91ad5bc8628f3f716d922b59ecfdf4fe991d2e98
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:1a582c5b3f2cedd106d3878e3e1595e4a76f953c67a751e55a65e71fbc575c58
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:3ad7db19767a64eaf708a9664b5b61955840c707da50b902e922721545bb8261
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:ef67a0c87361befd9ef7cee9d9c18731443ef22ca9dfe2484d2f055c8cb8dc57
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:630d6ed821b52fddecfcd7290e5e88c06e60b6d82e642dd25cceeb388e8c93bd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:d994c688c7c1e2b22ade597c1cba357b628fb9a1dfb1a9a4e855e551409dedc4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:b91b440632c0baae208d8aabe595839de285845cae3faca6d8bed5f22d4f82a6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:7468301b7df056488f1d55aa93dd9f01dc897339ec7ecc705ee04a3348168640
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:ce66bb57b19419fae1579f50061d16254a314865d3a5108eee31bb9c5fb8fdd0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:f84448181d90183f3b968725d359b4ac1c02b2ebb72f2a6cd44e961ae40c30b6