Sign inSign up
Node.js

dhi.io/node

Node.js 24.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

24-debian-sfw-dev, 24-debian13-sfw-dev, 24-sfw-dev, 24.21-debian-sfw-dev, 24.21-debian13-sfw-dev, 24.21-sfw-dev, 24.21.0-1-debian-sfw-dev, 24.21.0-1-debian13-sfw-dev, 24.21.0-1-sfw-dev, 24.21.0-debian-sfw-dev, 24.21.0-debian13-sfw-dev, 24.21.0-sfw-dev

Index digest:

sha256:672b360f50c8d83c7327465f232f2d0c18ef1c2ff1468c852a0143c3fd290dfd

Manifest digest:

sha256:62eb600423c3ca09caed3013e3e15189317d9c872762477bb084f70ecf721960

Size

115.69 MB

Last pushed

12 hours ago

Vulnerabilities

0
3
6
4
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:85165fc74a2ec2721b847bd0d2ccc2e86c91fb6973fa033b009b1a0544f977a8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:8f000b66abb62bf32c8141d6fbbf1c0ae8044b83c87a7d4feb00f9ceabbc4be2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:34ee770792f9c4fd33911f10e9b071af50c719927c1d4674c37ef1ec8c413259
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:3e66102cf424b4b51f8b0dc6bb6a820ab801238c907b80e881b8f1f5bda56d3a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:ad683092a3d52fbdf6221b771dc0ae8f612e91328b81032c91260a5fa93483e6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:036bd11de7b1ae1146caa8e00c90433a5e2905dfada13812621423e3e3c514a2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:be6d06fc45133ebf5d2468e763c78dca3e2dbd0a2b89767b55139a97b118ac0d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:15d9682bc9ccfcaa36effe51ba4bd314439e0a61615f3cdd5a181157eddd199d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:450e8da671f79f63902411457d75eaf0fc9fcc7cd812863c04b9e6fcb9294355
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:baa25f7228108e41bd182a979832f1451521b1addb2d41a617823795abbd54d7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:6e1b15fe4c6cf11d5e1f29b14df8bbefa1674d80206fa3900e87ab59129bcd97
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:4c76ca50644296ebd56c1a377f4df7ac6914a500676fdb01202768035bbc1475
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:14e6902fd5bb41bccca44f89c9efedd4ecce77ca8a9a18795484c47bdb0404f9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:183e94d19c2e9032c96746f8eedd4accc8b1a8e4584db849bfdb0c1d682858dc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:a84a67310db20017b2653cdd20d500c89169be6e2740ac0b152f46543bc81138