Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
alpine 3.24
Tags:

22-alpine-sfw-dev, 22-alpine3.24-sfw-dev, 22.23-alpine-sfw-dev, 22.23-alpine3.24-sfw-dev, 22.23.3-alpine-sfw-dev, 22.23.3-alpine3.24-sfw-dev

Index digest:

sha256:49b5f258a3a56fcb54193d93b88a4455ae533d948db2da6786174dcdd7ba3bcd

Manifest digest:

sha256:2ed3c74a528c3146557d1e996d5f56a71b5ec746caf1199241126eb80efe7bb3

Size

84.53 MB

Last pushed

22 hours ago

Vulnerabilities

0
3
6
1
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:de3d2af8be3ea75542e19be2f3105b245c05677e34a6fff4fe05c693e265f1ba
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:7b98f019885618dc3fc73bcd46c567d258d66f297741b911883f11d1d09e10de
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:67f78dfb674940e2e56bd0566c7ce9d1fda73a4ae48964e548a4d6739ef1a375
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:0fbb34616ea5fc8aa915530a9176fa4ce51df8968bb00ac4b82c382c683000ec
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:531694ced66a0de9dd33e881b828e56135edc2dd24d369fea4be2d12bebe6ca5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:e47ac05256452edb82bcffb74c92bfec0eebd2231fd5f17fcb9d8509c0a21b90
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:a7dc03ccdd82e554f651a4d1778b321d5513ec7f5d7438e8d43a3120ac9deaef
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:de47f25c30a2ab84af5732f49f289f829e95a6f732921970308849c44f9930f3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:bfac2de45af11b3b2e0b3c7a8a82aae9d421e56c88d7d174d504eeb621725b01
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:c8752e35c287e2350620d8ae2da761d6ab0f2998d5255fc8dc204d677e12279d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:914355f184c66d9506c09f1caac552c0424e4f58bc107bf8950ceb5de3f2fb89
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:075d0d285a97a08654ecda5745d94491f351387028a61c51c4fad11e441c5be5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:30a828ebbb14415a8542af4f1e9ad4f0180da17658c5b4e9254131b58d3ab87b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:8c66dbf09735bfe42720dee0cbcc2feafc1f41f9d7225177a3b8d884ac1ffeb5