Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

22-debian-sfw-dev, 22-debian13-sfw-dev, 22-sfw-dev, 22.23-debian-sfw-dev, 22.23-debian13-sfw-dev, 22.23-sfw-dev, 22.23.3-0-debian-sfw-dev, 22.23.3-0-debian13-sfw-dev, 22.23.3-0-sfw-dev, 22.23.3-debian-sfw-dev, 22.23.3-debian13-sfw-dev, 22.23.3-sfw-dev

Index digest:

sha256:9056cef75c253da5be8c82de79c7ae36cc835c2cb7de8b9f7d5d3309f7b634af

Manifest digest:

sha256:6f0d7836220d8e999404c3bbc4bf9ca21b12e4e67ea6fc44ce792eef49a15ee9

Size

115.49 MB

Last pushed

7 hours ago

Vulnerabilities

0
4
6
3
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:906f2a89e98d93584b8db9507e3d2b7fec02275ee4cb3723bb58a78f0c76a219
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:37fdf8f2d03cadc404f9e8ef2537d7d43f70510ac5b54d60814f6453cf7154c3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:d16c23f6f592d4b8f68aa29d9a2124260d3371a5e89e06d485897a62a8e9fc96
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:06c25e9dba17b70ed7fa45a35ab1caa9db50cdffca4b4107315596a8a8dc300c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:8f1710a6202ed163fccd58f02dc285abe723ff7630176e4b5e583f8a520a7164
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:01a4bb711eb29c8db16e555c57cacbc3f4f7a27b0dbe659498eb92bd1c689f23
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:091960e5b7048975fb4648c59c983f776fee72d5d6707356a247027a9ea3ef1d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:7d87575dd4f2c46404624add8125b2e6031f1bce99bdb0f857efa445b63f585d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:23cab3e212e2f78aa13e2d757c22b55fb9bf4e0a51ffea900b5fc23928ffa567
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:7790cbbb40ffd4e117429ea9f3166d4d42376a2e97fff1b70e3d6ca6af876dfb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:3455c558515824815ac1e6e4f2a1c920cde366a306ae7a5a9d0d6eb38a21292e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:17ddc7f7ac5eb344a2df635c6d9208fcdcb6ffcae9fcbc23376c3dbb06a1fac6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:4bae3924ec810b09fe32de3563b8a6cb8df9c79b9991b4b5c010e21077941a61
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:66522a638c1e02dbd481b97683d2f57d651c67e235e35e47c5da649f0de76673
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:4950e23d5767929a71b9ff0311c7fe85f054d1efe7766500c597cd8b087f6fa4