Sign inSign up
Node.js

dhi.io/node

Node.js 26.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

26-debian-fips-dev, 26-debian13-fips-dev, 26-fips-dev, 26.10-debian-fips-dev, 26.10-debian13-fips-dev, 26.10-fips-dev, 26.10.0-0-debian-fips-dev, 26.10.0-0-debian13-fips-dev, 26.10.0-0-fips-dev, 26.10.0-debian-fips-dev, 26.10.0-debian13-fips-dev, 26.10.0-fips-dev

Index digest:

sha256:517437fe68bde6ab8ea6294478a25c7fdf90bd80420245eba4fc530739d93bcf

Manifest digest:

sha256:85fc06de1eacdb5a63817ce417edb11c935c48111c59b20469aaf7e42bd5f2c9

Size

83.29 MB

Last pushed

12 hours ago

Vulnerabilities

0
4
6
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:9579c626a1b3c6d80b03576281357e64b88a30488caf146e27cbf354cc98bbbc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:e99be230e37828a9fae770007e553423c08132b739d1ab5eb1b7efa269026568
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:6daa5331f21742f3520156587c01db494e84bd0634f898a298a6ffb1286bae16
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:4002d191ecc7cba1a7822ab430e593a279f04dd555693c411cb31439e1a8ffdc
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:bee5769d6de6b89fc6a067911d00aa4b1cf2fbdb2acab2f3dbf7aa2c9d883f2f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:a19c6fc17cc0a247531937ff1ac648f03346b96c928c7d3f7597cf2e96329bb7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:0a3103ee7f45714099731c83c552d6687dfc42bfdc25dd881977add4ae234e4a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:cc3b50e03a2a21c20b3b7698eb865f801327e152a49ac3389a1b0e7a37c71305
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:7955f17bb46083379373f18055c0f49c839278826f0b321de933982329a92d13
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:59f05252504e756c464704cc3d7c90c063ae5e44f5ad7d6c6a5b226e46e4ed43
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:2173a0357dffcd389beba576f3104a5e0c0ff9dd5e6981e8dc2680ef61c946a1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:65ac0054cf8e24fd32be9c629fb44fe80bc0f618e90d3455188204958afd706e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:afe685a1e71c1d5cdb2fdf977971993877f9607107fa4ac7e6ecf2fa1e5514c6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:619faefe53d4e74005685cf8777aeaf14a4e717505f9801db3b1e9c93ebaed24
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:acf271db3c7dd9f439c0ae7f5bd9581f1ae1fad877de055e75f5df9e7dc9bdb5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:20f8a655b912cd49a6f32677f295e0b9f4cc4f8a287221dc4cadd6864b0c7a52
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:942509fd6d277b7a55e6249a719433f7fa76c39f2800215ec8f72ca0c3b5c6ad