dhi.io/node
26-alpine-sfw-ent-dev, 26-alpine3.24-sfw-ent-dev, 26.10-alpine-sfw-ent-dev, 26.10-alpine3.24-sfw-ent-dev, 26.10.0-alpine-sfw-ent-dev, 26.10.0-alpine3.24-sfw-ent-dev
sha256:0525feb653c06cc76561f52830293113faaefea638c21fc472ea1216ac826fbe
Manifest digest:sha256:42ba700d5dcd85486cc4cc8b138bd352c4b3cbd30f76451c730f9fdbd9365dcf
Size
91.66 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/node:26-alpine-sfw-ent-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/node:26-alpine-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/node@sha256:dc95f9f288a4c434e1e923b1365b593b3b6fa891ccaf5130d46ddfcbae7d9d92 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/node@sha256:41bcf936562685f5947e3421b388cc50af462ecb4d02d8635b2ead157f6b125e |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/node@sha256:682abf9b3337af0ba55cf76bc930f7783ecec6d86475303c4f1e0a142b7631b5 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/node@sha256:13f0cc9a46769c4e6df894754dd4b3dbf07101527cc94570a2745ecf46a93759 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/node@sha256:137e53136c58ac9639ab705d9b3547db92c539bca5ea8e8342236804df6cc460 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/node@sha256:ffdcabba8329ddaab93a3883a4c6a7cfd88e195fd1423a9cd5a88ab84dcda597 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/node@sha256:95e3266739c46442327a54c11cdb4d5cad968cc593ad9ab9fda8180a1a7f9b3d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/node@sha256:ed94ce2ffcc56e3c31b332623412e9129f8193b753a67d11ac0904445f071276 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/node@sha256:ab04e909ea23d434c03d84871aeafc0d9920d9e0a8024003cd8b2bc25bbccc3b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/node@sha256:b4d6155992c8eae07fbe633674cbf998a9697aabad1a699cc722dbe95f0c9e57 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/node@sha256:dddca463c196dd52571282bde5afa11f68135c8fc32241d89b077e4cbfcc3b7f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/node@sha256:1852ac10ce0268d6146c94954fe2a23b033e6df33ec65ad788425f1b182c85db |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/node@sha256:52a4270d77c53e85ae81f3415044ffb3d0f98ebca2a2d632ccbec2dc8960b0f7 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/node@sha256:636fcd1be2a7faf7902cccfbc69005b32924b1a9c1c683af7b5c70567f53585e |