Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

22-debian-sfw-dev, 22-debian13-sfw-dev, 22-sfw-dev, 22.23-debian-sfw-dev, 22.23-debian13-sfw-dev, 22.23-sfw-dev, 22.23.3-0-debian-sfw-dev, 22.23.3-0-debian13-sfw-dev, 22.23.3-0-sfw-dev, 22.23.3-debian-sfw-dev, 22.23.3-debian13-sfw-dev, 22.23.3-sfw-dev

Index digest:

sha256:5e1f1c1f2798df69e232fc97d5ebbd8fbba85115b573df0d3d7464a2a8c720c9

Manifest digest:

sha256:e75dda4dd32f3a724da6a375fff4b206c51968529912c1a398107db335608599

Size

115.45 MB

Last pushed

11 hours ago

Vulnerabilities

0
3
6
4
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:5c131e714909be827f89ae2376193e28cd08132361cc4096c2fe630895793dd9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:9e2632a9fc252e06104aa9e21a4f3e008a4df0bf62b052669ddf2c1b41b21f0e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:5da8d6a069d14696f0f29708288c756b276a57cd13cfdb4223e17c0b7822d538
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:10dfdeb2f5c63675c1adfc34fa9c67b1dad55c34fb9bcdd85d04170aa8a26f6a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:cd814673b0ffb2b908f28b2348c80ca86d8b01c3b6aabff92563c246153abaeb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:ed5220b29d87a072efa87a88bd737dbf491bdee32c4911939377d3b0755f7d5b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:ff8875b429a4d6d88ddd931d4442e2c9c5b7914b8b1ebfbf87199c004c48a470
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:c8c3e740baff06774ca9a66b92d8fd169109c57b8724126cab39871dcf6666aa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:7669f87abc890287bedd905c36f7967aa3666bb8d2e8de195a65446f5db7ddaf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:164235c21afb4a49e773d9358ffc9567b1b767d273984ed6ec9311e5d760a9ad
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:b3127185f37df9054df675e34df4f587ebbc75f329743a36c1651eb925345e9a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:ecad619ec937d39a5699cd53c86ed34a0e6815cc31583382d915ef7c654c6434
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:8efd1debbb9e6efcbcfb6546a5115a93824ba11e6f3ab68720d1b730a5917043
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:487ed1bdff5d0889cf13512cf93dbfe270b4c45e346b7f77568979700e99263b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:dc266609efda6631480677221d14dd4dc2a33f39ccde0106cc854776aa267d9a