Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

22-debian-fips-dev, 22-debian13-fips-dev, 22-fips-dev, 22.23-debian-fips-dev, 22.23-debian13-fips-dev, 22.23-fips-dev, 22.23.3-0-debian-fips-dev, 22.23.3-0-debian13-fips-dev, 22.23.3-0-fips-dev, 22.23.3-debian-fips-dev, 22.23.3-debian13-fips-dev, 22.23.3-fips-dev

Index digest:

sha256:8646dd1cdbfef0c6651d0f248b451a26cb9f1305bbfc7ca60937a8116412cac4

Manifest digest:

sha256:cd527265b65ca993da50d8c1e42d543abcf1c9915c7888872a6575794c9158d2

Size

80.49 MB

Last pushed

1 day ago

Vulnerabilities

0
4
6
3
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:6be57d672de8e5524f6d3e5669f767fc067ac29e47143d4702ba584dca1ee828
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:32caa2fff086ebd1e2c06b3547f44751d88c24baab8b7643bf0881c4e86df429
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:f062785b93b0cde19644a055984600c5044f5b0b7e4b94961e2b40c2bf973a8d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:5171410ecc17e9b1e369e16e537f208e99eb067490b0e9fb1417b7187eec0568
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:67291b9037f8ea001d81a1b4c1cf14c1b07319d688bd4eb9f819ea653411ff93
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:e69eb4e91bd8e31370a338f27962ee65c9686b60ee60067ae8b8f329378b5177
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:984fa7cf3b8a49fe5fcfb460f55fd619602b2712d02757804f27bf5c4c5c949e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:c3a9607af6c8f44bbd3fd3ed4ac58668e629ae830306398b24aa338124cbc18d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:9df17d7e9b715ba0bac2dad360ee8f6dacd78f9be79f8b16159d8cacedc6e929
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:dbe4dd4da2d0b63783cc051dd1c1ec6cc713b4afc59bce9505be61478ae8a8f1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:b9ffedc2b225c935fcc30c8e0ee3a51e7502788fb7bb1dd58a1755bae673090c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:8774f725209e29eebe0742eca8cb3a2cf7ded333825c88935909e7f3a0a7ad49
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:85db72aaf15cdf58f216ee2749bc7255cc43f0c29f5099111da87b9e61853737
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:6c97580a9b5e0e0360a06f6a369f6668281e3782b89129bf9ae58deb883b6c18
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:efc9c58db4f600f275163db9307b048a49be048f4377779ef9dc21c6782b6cd9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:222c5a102fa7ca2ed2df2b9a152b379dd7f29e462de10d7f65282971a1a83603
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:dd330e381bff2647d738c6be729cd49c9c7090aec4a6aa869b371e3264e85490