Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

22-debian-fips-dev, 22-debian13-fips-dev, 22-fips-dev, 22.23-debian-fips-dev, 22.23-debian13-fips-dev, 22.23-fips-dev, 22.23.3-0-debian-fips-dev, 22.23.3-0-debian13-fips-dev, 22.23.3-0-fips-dev, 22.23.3-debian-fips-dev, 22.23.3-debian13-fips-dev, 22.23.3-fips-dev

Index digest:

sha256:6b0512e8719489dc27ebc4d1d3a0e7878a3fa4a434a4dfbcbe53005104a7a33b

Manifest digest:

sha256:2026b10eef7366341732a915b5247ad22b172c395d675b3d8813669785f749c4

Size

80.49 MB

Last pushed

16 hours ago

Vulnerabilities

0
4
6
3
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:6d6019f5ba3fae9e443a09638631bf79845745da5d017b4da68ff8f56da4a99d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:29eba7e68460d40039b5faac4e8b6e276e9ccaa9a8b48986eca35e709ec6263a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:a644eeecde1f1c3bf0cc7ef418f76ea8240eae9ec397a42953a1fbb3bca46d06
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:1e2cc56fdab035c27e8fc4336cae79722fa1f86156ddbecbfcbd57cdfbb7bafc
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:76c7c2677657509439889faf0c9d26f3d6490634427d081588f62368f0378516
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:dc38b48ac201554e06a96cc542acf7f0edb66ad19272f71dbe8598b2f8da998b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:ec15bf14898857722d5c04c6e70e850ee017f4843e8f3334ce6cbe63ae7b7f49
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:5ef429c88a8afa9ab4e35c273a1416d5b5e41af9865edc73f3c5929653dd245b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:d4153a1b7a682be9e2e83242d63a5df2a5fd5a9594c4117f3ecdf247f5a0facb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:3394e6b46893c5e1ead635b3f7914f3e0b742d81c7fa9a219d1f799516f68c22
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:8f655323ecab30cd8f3edff7caaa48d7018fc7a6e8a80ecc0ae951ffd6bd262e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:56d3c0e819a9c5e6299a12f5c7a8e3dbafeab609797f02afcd6a8d3f2fbd479c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:48301aedc6a32e0bfb4290d480f64d4c0e2fca610a8c80c98021d2d361598462
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:05a91714f774421ab4b53a1c48bb372d0590fc18b1202f928c721e7b98512a03
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:522d251316f618007ee93adacfaceb1fb3b5d3fe495b7f2dc285c0e734d57cda
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:e465ab9927519a77ce0c7a2c0862d7fe475307e1b34f1e16d229eaaed3c3ecdb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:650c426c65038d3fca5e697737f684e22a8685a106ba60fbe447d31b2f092d42