Sign inSign up
Node.js

dhi.io/node

Node.js 26.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

26-debian-fips-dev, 26-debian13-fips-dev, 26-fips-dev, 26.10-debian-fips-dev, 26.10-debian13-fips-dev, 26.10-fips-dev, 26.10.0-0-debian-fips-dev, 26.10.0-0-debian13-fips-dev, 26.10.0-0-fips-dev, 26.10.0-debian-fips-dev, 26.10.0-debian13-fips-dev, 26.10.0-fips-dev

Index digest:

sha256:e159bdfab8f6c987b3cf1a9e779599de4c663b314626159473742097ae9f323c

Manifest digest:

sha256:17dcbd277eda27994c436cf8fdff0fb58b03d64e098130e45bad17171ad91449

Size

83.28 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:f7d6448bd197da27106327c1bf20e7d0ca63ae60d627e0fc10ae0afe956a8eae
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:38dece8832c65d3dee6d8c2c6a949154551aec97fc67cde46dbebc6c341769fd
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:2bcd3a9921447f3d4bc03fcbd34d59ca293de1532cbd844a3a56c62dff52e50d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:85f8b8dc8fbe86c5b6d76e171a40d61d92665ee642ab2dd73379f141452b2d54
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:bd716b6f828efb567f34c198135e5a022f4ac0288f2311487a4e6da8d3755eb7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:7cb59a2adb6375f50285bda7c37d0ea5d4293ef79d6db5e6b5eacb5a1026a7e6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:58908b7617a5b9cdee7eed8fc32b1581bda04e660f3abcf4cd6643f70689c346
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:6c0dd96acfad58e89922a0e04d3b9017d527724d1ff8ad9ef53db8103c81073f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:530694d2d45714042e341dd109cd34d8ad00f83929cd7287a635428b0f9861f7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:fb41005d60ea6a58d8d95aaf38b7ed6c3e91e3867e676c4a468d1962d5cee8de
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:0643d2f8ddfdd2d3c7a9f200ad390b0791ffcd317dee371716a3548d55404256
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:e80a1b5756ee12675d091dad9d12c97426f79966a79685c1099dc884203ddbbb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:04fab5b2dd8c7c2d4c55a8671edd1ba08fcf972beb2a945b64ee0d4e7c336b6b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:3790d37f7a96c36adce4bd0c6069edd0cc94bb0bd58fca267766ca9fd6367898
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:e171371219e360f3ef9048ff94dd1c016d69e23b5b63994f2a0581c6f9a54039
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:c2ccd1633193373b0aae2eaf969c55f1a8b2c2f1657e9c947ef978be1e328249
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:03e19d731714b138514f92d94e06de2bcbd55c84cb564c150f3503913136d217