Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

22-debian-fips-dev, 22-debian13-fips-dev, 22-fips-dev, 22.23-debian-fips-dev, 22.23-debian13-fips-dev, 22.23-fips-dev, 22.23.3-0-debian-fips-dev, 22.23.3-0-debian13-fips-dev, 22.23.3-0-fips-dev, 22.23.3-debian-fips-dev, 22.23.3-debian13-fips-dev, 22.23.3-fips-dev

Index digest:

sha256:a121431e89e2b27b7d41209b92347eb63fb0c771513f8651d6b85a7582f5e59e

Manifest digest:

sha256:ebeed350cc44f9609217c200183dd99e5cb0354956b15ea70aa62e3c2718cfe0

Size

80.48 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:6c4a42880a6f361c31c7f44db547963bcda2c072c8599ec43182dd8b3b28c88e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:aabcd199960004c38928eae36074c3bdb92e56f48f7c62311e517bfad3dc6161
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:258b3189c717dcb918f7418037f0f46af51e693b65b193ba6cb96e88192e135d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:1ad5184b6f5f1e2824afb4e22b1ee713489782c1e5318cf41bb9f2a424810657
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:07420c9d33fb2bdaaf8579fd3df9e07c2d4aeda752c3d0b1b26b7923ee83fb52
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:20929595b2e3a9e2885e06156cc758b884e2f8b69ccca5685bad772c401e611d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:b5c462d0fc0c7598ebe4f6149a5ea594a1803c28ab8b4a1e08bcf6f61816ae31
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:0e256deffed5a6fd04828d517693d07e840f7d022f38394e8389eea217be6f19
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:09f4bcc6ba79d80b13f35f9192602d482b63ed65a72af126a3adcbb93fc1b4f0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:3787b67cbb545ea52376478ab75d7ee3e07f8ed9870c00584fd016bd3dd3a103
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:0d109bcae49e1a6c3144c5ad9472fd6ccbd834988348adf2a00baa55f4ff2957
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:276586bd9e6b1d429c5be7d674298d569a6a81d860b90e1aa7b041b378488992
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:1677b5bbf158fb223a952c9eb177beda7308e6645d89e34ace34945829f1044c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:0d88ef88c8d34346bb4a986fb81e722447bb2a84ab9f108d7986a63544167a0d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:d703112c938b00d9ef8d359ad70011103a199b399001a268d3b82123c2281061
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:177a8a523a645db168d78855b32729db3c66bd206a1974c93760c1db3300de38
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:725154f6c059b08d8e881f27c1f13dd17196101f5ab40a88d1c5547417af65c7