Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

22-debian-fips-dev, 22-debian13-fips-dev, 22-fips-dev, 22.23-debian-fips-dev, 22.23-debian13-fips-dev, 22.23-fips-dev, 22.23.3-0-debian-fips-dev, 22.23.3-0-debian13-fips-dev, 22.23.3-0-fips-dev, 22.23.3-debian-fips-dev, 22.23.3-debian13-fips-dev, 22.23.3-fips-dev

Index digest:

sha256:5385c61930548f2e9d707336246e9363188f62c561108688cd91a1aa308fb1ab

Manifest digest:

sha256:b26692add149afb9659f92e44d4696f6fd7ebd0afe2eb2023cd07f48d65296ae

Size

80.49 MB

Last pushed

10 hours ago

Vulnerabilities

0
4
6
3
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:1f7f9cc143fb26eb0a280d9303aeb60a7cf15c18724a8716a2d500fb96bf8ddd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:cc57cbb04c04ebfdf444511c1d3c39284577eb1a5ea7c436bb7fda482b48f819
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:e4287ecac6c8f76872e889962aa3fa4832317e9f92486b21ac751968bc9dbc31
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:62df665bce1fa0af8033d375d56d720133928164bed67b9cb4f3df0808707184
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:ef9c41a77be8c334dd1338280e16b1656340dbdbce8ad25e0694d62b814e0d2e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:4cf927f05a03bf02cbfde84987f370b5e34c6a14554a1a59b87fd3b8da7fd8cf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:90be7c51c10742f6cba8c212bbb366a4b34c57dbfeaaaf31c0ba81948bfe94e9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:28f2f002d7528778bd712532320c1accb6506e5503060c9acab1b948411946f9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:202315770f054a7419323e8c30dadcaede25b71c5bc64b1e7d1ccc4c85cc148a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:6a571c0a0b290e3c66c39d0286ef711e164e12464996810e0d7922730e987bdd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:a828deab7a36cd76a3eca8d3c0aebc117420ac0ea154366efb8c96164a7bfaac
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:d2499698bd185e7050084e6127758ecaa92fb32537eb6689af267cd0b43febb9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:c70145cef68850364b740c4207beb70ef1f1b91e0a95d5f40e315d6f2df29ca2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:20bd1503b3e772969206a5edfe453bcd381c297dcf86c8b75f9f586eac0e351e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:8e7d7c88012b30beb41076be2617bf6a2fc58b16a80f0b43a6a7aa02b9d970e3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:56a7d55638fc66c1c3ed8abc6d57c486d8f4c0ee91ca505399941339ab84c893
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:247418814c627a58c065244f649400e195a5ebef01afb70cc24d749599707142