Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (dev)

CIS
linux/amd64
debian 13
Tags:

22-debian-dev, 22-debian13-dev, 22-dev, 22.23-debian-dev, 22.23-debian13-dev, 22.23-dev, 22.23.3-0-debian-dev, 22.23.3-0-debian13-dev, 22.23.3-0-dev, 22.23.3-debian-dev, 22.23.3-debian13-dev, 22.23.3-dev

Index digest:

sha256:2c92d00373e78ce5f06cf9fdd4c25836892c657a9037ba4a3ca51f87c199c54e

Manifest digest:

sha256:3902fca577b95d1d66214313279a6a9eaf46e13514dda5d9efc12ae2605e8bb1

Size

79.71 MB

Last pushed

20 hours ago

Vulnerabilities

0
5
6
3
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:52a2952906e7ec02504a839b06c4d4ba08e3534997028253dea8bec0f03e76f6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:38b88e8fff4fd4ffcc9c2331d6066164a660c3f160b531a2d8daae377ef6b99e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:ce41390cf5fbece97985998015e73e4cde41e79cdf684afb8584d86c71dc765e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:8812e8080f8138d81980375a6298ec0e0c8568a8fc9baa3b7631f31d40abbf29
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:1a3504d65a27211c48f96d6e44c93eff4d811aab3a95f94339f2f999d4f7827a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:b88c2d1849139caec7a9358c9d1eecdc5a00a36bc595f520e4c20509bf996759
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:ebf34b3ee6adc17aa9eeb2ae9e99321f81556965f1b22f8836afac2ba25c8dcc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:49d8d1413735c8b1e1032e847bee821baace5dd88efae7e931d7caaa052c3b3c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:3c4082e9df7e99321cbe4f1912a226327d0091ef6a16b5f9ec7c80c5a5a9bea1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:7ba46e03be06d8c73ab21658d8b61f7bccab2061b37713c72c3842c511ac9511
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:500dbff2a54ad71eb1f413cfc1ba8e9bd6b70fcd93d035d4545c83b2926341ed
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:cdaa71d246d3c102eef9a3143dba84dae72f035c51e16968786f12cc5253c89c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:cee92cacbf51cf9d9750c7f85311b9719de29ad66c099e9b2358244588e9924c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:6c6163f94ab4675759fd5460480a03c44b99172f8f0af667785d24a50c4432bf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:95e2ca7f3cdb159aaba6574d100359cc7ba267d976acd949e3c9f9d755b1d9c0