Sign inSign up
Node.js

dhi.io/node

Node.js 26.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

26-debian-fips-dev, 26-debian13-fips-dev, 26-fips-dev, 26.10-debian-fips-dev, 26.10-debian13-fips-dev, 26.10-fips-dev, 26.10.0-0-debian-fips-dev, 26.10.0-0-debian13-fips-dev, 26.10.0-0-fips-dev, 26.10.0-debian-fips-dev, 26.10.0-debian13-fips-dev, 26.10.0-fips-dev

Index digest:

sha256:fce26dbd234960bd935b1e578c7c8975f9329c878fc7f78a3386fe24c9922259

Manifest digest:

sha256:fe7878f5920ba36274bac41e82fe42aedc3fb00ad325fcca6b00fe2f4fdb1003

Size

83.28 MB

Last pushed

10 hours ago

Vulnerabilities

0
4
8
12
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:aef95a7290fa257eac397bf9ffeefbfa049ee9849d7d09561a1f4491a110f9ac
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:dd31d3852b853767a70750ebd1ddb13373c939a96c1532f874e7188e6d25a316
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:235bb4aba37c06f8809a8eb20e7c99212ed6fc095af38fc1dc14a29a8c1cc2a4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:ec47536e12bbbf4da698d552bc157ab97d4fdaf98fa64907994d1c81ac75ca07
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:f4ee4d194d3b730b60bcd8c500301624343e04ac98e7f41e8ffb12b29ab5c4a2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:4617456144b8fa2c9ad24cdfa57e4bfaed51beffbb8b3cf4ea1e1de4c9924ef4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:f0df0e9474d42ca03be5ef08e0b8acdfebaa0471ae729f7521601381e7b70e0d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:a84db80635a146debb234c8fe348df238ffbd502b9f0200c1260fcbb2ad9a0b5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:b61833d2ecfea387fbb4f6927f8b25e5d70329089946d99207a8bf3ad54924ed
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:475c68c27efb966a19a6d5ada0d1fbc48c0f7ea5b78c8175137792818bf13f6b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:d5d2f21d46fb19e37bd1708a9eb44b3573126c52decd74cc957cc013a2236d15
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:874036f7d99788f916006f9d5325803a0161e125d5b23543fe2562820a409482
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:58c882c391da5814bb808158d521af257f770739c2dbdf4cd603953534e31e83
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:1cbee4615372757c02e31ce563caae691a3473f477e7c8d47dbf70d5076c8c8f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:bba91b645a20bda005cc70ddb173e9d4fd43ad53fbcd96a37429ca2aa2d74e03
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:044ef57e4febb6656baf0c882c317371f8ee651dadf7f0017b699ff5c0157a05
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:9e4eb5175d92ec6cca7dc3e14882d9dcbacf7eff1035f6057221a169224f0a71