Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

22-debian-sfw-dev, 22-debian13-sfw-dev, 22-sfw-dev, 22.23-debian-sfw-dev, 22.23-debian13-sfw-dev, 22.23-sfw-dev, 22.23.3-0-debian-sfw-dev, 22.23.3-0-debian13-sfw-dev, 22.23.3-0-sfw-dev, 22.23.3-debian-sfw-dev, 22.23.3-debian13-sfw-dev, 22.23.3-sfw-dev

Index digest:

sha256:04d7ce26aa9b6ecbf801d4a87eded7bf5ae563ce05dfed181b75ef59fcfc3554

Manifest digest:

sha256:0c8572271f4c4752ca7fa2ac0e8b16332a651869282ed7afe3fe55ff550a8d6b

Size

115.49 MB

Last pushed

10 hours ago

Vulnerabilities

0
4
6
3
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:ba8d34a34d4d40341632127063e7937d167b4ab4b10b5a0b2fa7cf0ff3fcd7b9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:f6a4c8efd34ee771485d9a8e17d298a3cf44be4964b95c628ee473a2c3ec3219
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:0804690619d9c5add5deaab2bf83663ebb883199a49ccb6dbd6d458ca715fba3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:78104f3f133e1b2bf34952b54263cc002df1eb0900aa7f6a8aa27d1e496ecee5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:7ceb8ce3b71c99ac01492018e7516b764bf13ad1cd6afbd9202bdb5779c0d8e5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:bd48a96ecb1808f17c113fd987b20b50073b0a36998a4b7266d1f140ce2e07fb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:1bf726952398410470d413bf266daa5120486c6a5e515f9b6736a7b6e5ad5e0f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:b2e7412f44ea2d2870b512b9287740b76ca54330219437796e6af8e44d816eba
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:ae41dfef6fbc35df0a1866711fb02076f4624da22546a8d17a5d384a9a655751
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:814777d287da4916afb28c24c80f63295254b76df01eaa6341e57501059fe498
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:1d1925af7cbd979961edc4a9f8e44db628419f50ca7257843388f19df8e155f0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:481dbe6c0aa4b8cfa6459f8e1ab76e2bf7113f0b4d1a51d8e512965687c0fdc1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:e86eec732bf03f5d0455c3492e94a23274f5bbbd2211e6995555f71c40de57c8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:a37d7375a90d1ccbf69aaf7e542d534e807ca7c98cc3fa70171cb3b47e2f1eb5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:31795477ac9645360c222491c86b122d2340f4584ca42ba27c069ce8947815a8