Sign inSign up
Node.js

dhi.io/node

Node.js 26.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
alpine 3.23
Tags:

26-alpine3.23-sfw-ent-dev, 26.10-alpine3.23-sfw-ent-dev, 26.10.0-alpine3.23-sfw-ent-dev

Index digest:

sha256:6a63b7fe1b8da3e7e1a534aa303446ae3d6f218ea11e8ad321c52024e703d69d

Manifest digest:

sha256:7e95fae0393330fcb8f53bb551394a15d2dfed59c4472f10b39970f2ee4dcb6b

Size

91.68 MB

Last pushed

3 hours ago

Vulnerabilities

0
4
6
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-alpine3.23-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-alpine3.23-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:6d139a311efaeae68d9da7dbbbe7bff2d1bf984e47b1471bee5063ec95072b2e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:0e876e74525c91cb8277858e7fbc1651962def0dc794c40f4393a405ca93f521
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:bc98cf1b7e69cadd3989ac0bd9553d3fd9c8edabcb7dd633311ade8d4214f2fa
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:234fa9ac8bde07e624840a57265bfcf507c812bae83c60f1822370cda6a548b5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:5af420afd0f9577702f5dbe4aecbcdf009408b334a6ae026117017597dfc5a3d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:9330b758921ee36f4edf2cda39b0c0226533f6249692df9716d0d59e4168319f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:c48b1175edb7c535427ae143497ac43060a58e90ae5e04e7397aed735b4c4eb9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:7780a238d9189cf0b98316e87b2a18112a4260e5c537f2df8ecf9aa63a486b98
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:3fe36817bbe1baedd7aa125d8d2e5afbd2b9761a4534dd24aca4dfa9049265cd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:c2ce952c8212a856d980df7197ea80b10a01b6f7dc828ab8723eee3058aeef0d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:4fee6301a3942ecbd13c00563de237d62c7fd01941d502b5d35791bd5d3e2e85
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:5e06be413f6bd5f790ea3e230c10abb512ac5e5df2649813cc7f553abb3ea16f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:b195befb6d5cc17acfc18ece6f7138c77d10fbb9393b2b4d506d4cfe1d5a850d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:b8511f6f412872504be7f10da0c4a3b557238c89520d980c2964bd96e9b5d778