Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (dev)

CIS
linux/amd64
debian 13
Tags:

22-debian-dev, 22-debian13-dev, 22-dev, 22.23-debian-dev, 22.23-debian13-dev, 22.23-dev, 22.23.3-0-debian-dev, 22.23.3-0-debian13-dev, 22.23.3-0-dev, 22.23.3-debian-dev, 22.23.3-debian13-dev, 22.23.3-dev

Index digest:

sha256:946a6c0fbfaf0298b52cdff378ca8864c2fa12e3b2a16abbdb95232b2508adad

Manifest digest:

sha256:74bba7ccfa3d643b26e076af9a3ee42ae460840f9a0f5c5c39580a82fdcc72cb

Size

79.70 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:ec667ef980a397321cb41dd135a6147370353de7007e7dcbda8a002695f73e7a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:b56314b8b40ec4ce0d661170da1beca37a8a10dad39e9442b02dcd70ef52a57c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:f6b876b52c9ed4e5b038713f8b511ce28924c78f86bd1b33670f30f7f132476b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:7ce6e81d9205b0b87e45c14e2a7a84abe12fe3ef1e6c134aec473963979d8fde
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:a5c30411ec7bfa53a1b3f595e160c86e41965c1d7d22766c405a61cf83c092e1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:152a13cf11afe8d5a01aa402dc815a6d377948b3bf38a21ba464abc9fd22d744
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:d77f5c34290db2b0315106a4eb5ecbb63bd03f26053537729ad35571495afc3a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:434819ac6387f7495c2efb285c825b23e5686795720d43dccd810bc139ab561f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:75fa48061430ad4abdd24dc6aa21215bed2112153a2b670cd4286c8344060f13
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:6d9af9ef44e51d81c89a01c735eea5886e474901a0705f5629383430fd03d429
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:5863b671517b4f1e4ed26672f6f2959c929710c09c453a89893ca67f0020eda3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:5d5c3b55eef3dc9b54f41c4f04460a393bcf22960e0db6fb01a3754d21843b95
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:712860a20790c17c0a44b56240ac447428f6189e5d93dd250bcb41f089d95aea
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:db7e481bf9d631347eb0e0ff7b4805166083cf4804bcb6af3b8e3507f0433a28
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:803a9dfbd9c878a8d5e2a97b1801a83909b4572e373e84fed9810692bdd30cf7