Sign inSign up
Node.js

dhi.io/node

Node.js 24.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

24-debian-sfw-dev, 24-debian13-sfw-dev, 24-sfw-dev, 24.21-debian-sfw-dev, 24.21-debian13-sfw-dev, 24.21-sfw-dev, 24.21.0-1-debian-sfw-dev, 24.21.0-1-debian13-sfw-dev, 24.21.0-1-sfw-dev, 24.21.0-debian-sfw-dev, 24.21.0-debian13-sfw-dev, 24.21.0-sfw-dev

Index digest:

sha256:7c317009dfacc5ac2b5b8193bbf8ac0f9dc1cb5119069297df2b54a61f12fbae

Manifest digest:

sha256:b2b4025630d55d884af776b764a04856a7e106e85ccfdba07de00692ce859db5

Size

115.73 MB

Last pushed

1 day ago

Vulnerabilities

0
4
6
3
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:fe7e88ecb2b9ffdaa396f43b2dbd3204e81b71cac2963c3bc019d09bd51ec63a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:a3105c25277d0b27e35d6ca9b9afb18db4a5931016a4e72dcc634ba42d102b2b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:b3cfb71d7e42575d9bfe8e37905d8ebef5b7e5c723fa7db4da6388b7f1331ca1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:8b59c006fd35d3251abb67abcc1d142d08dc43bd40019aa78e64a62e3591317d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:92f65e20bde1c1745125af35b90a06441b0aaca73e4cbb54e9115607882b5065
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:d1ac444e6e4fef1c954462831a7dedc64d24b9f970a475256c6bafb112f7a1f6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:033e0983487c7f80a10898f1278cb8682de87518371c9643a5ab3e74a02c8f14
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:68339baca01a1ce1b83c00cf0eb49d386031f5e5a05bbb561d8c389b40ac339b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:4200ebf5c4839c07f959a551bc360bde81b5d6694a3ad3d30cb45d4784509615
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:e32cfa90354af186d79e09ecc0f93bbd720f44634dd5b9f4784b6457daec2408
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:f230faeccf01c002d8108a8a59437bbe05b4fca232364e18b3a0b2a3c701c4de
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:141c8c0cd7f478a84312ed31f5a45b7b5712d8675fbe7f2dc7d3b3f3f8769561
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:1263ecb2afc77304b1bffbaeb4e02661892484d03d74d09eb96b2efa53b911e8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:003985e5dd9b46b84fdaf34696a3112c9f7a5e9b3202d019e9d235b3d8fad053
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:4be881a8be5e29e1f3e8764ff1f58e47be105df9651e975bb76189af247af098