Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

22-debian-sfw-dev, 22-debian13-sfw-dev, 22-sfw-dev, 22.23-debian-sfw-dev, 22.23-debian13-sfw-dev, 22.23-sfw-dev, 22.23.3-0-debian-sfw-dev, 22.23.3-0-debian13-sfw-dev, 22.23.3-0-sfw-dev, 22.23.3-debian-sfw-dev, 22.23.3-debian13-sfw-dev, 22.23.3-sfw-dev

Index digest:

sha256:cb16de31e9ea6c4b9feb068535813786c2d41ccb72ebffc275847947a8657d8c

Manifest digest:

sha256:2d6233c3b2da82f3a5125744013603df01ef7805f862f06261dd7ca7628afccb

Size

115.57 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:26cb1e7d5aa835457d3bc964ef0905d4babe97b652b6492f4bfa3eca1beb9626
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:c83173c640d62cc77b53c22b396db94039f544214067dd6003be5299bc8135b1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:dbc2024c95a10520fa7a2a267405021e919482383b30afc135130aae01313f3f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:bd185365750880678cabe9259fd806278b62aec5166c1278017a5586f82ff452
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:a06d5a717de29721ac83aa83fc2752b2ffee8e34dfbcd90a4d96371363ed787f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:1dcdecb1400c055735b8bb3a7b4c87d9b5a641ec99409fa4afec678dce48912e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:2e10f9c15fd729bbd69d84c8aec889ecb9abaa4fde3c5f6cb87d8a050f1e1e71
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:76d3754b8b7b0d1e763dd0647b1ac14eb935a62d607a31c87c611849263ce632
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:d16c91d814484081cb2293787c96b861de35727c2155567e7728d159f6729936
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:32202f22d06207904812a342a118771c43d20ca78a39a3c16ae77ac498cad196
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:8453a6ce948c418299a4c153f98ca0923d512bb49a2ed322148df68b00c4364c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:b3a07956763de8756d9b128aa8ce1459fddee6ee97d1a45eee77fe284deb971b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:9a15516f95d526f69fd2d0cf0a9a2056024fa868640f5a1b2c4e34571463a14c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:79eaf808e302728abc4ec8ad5865f5e4460793dbfeef6be7fa162f3d0d11b4c8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:118505259f56ce15a507c4a1da92d1ce44f122d1d2a625adb68028d3f98d4584