Sign inSign up
Node.js

dhi.io/node

Node.js 24.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

24-debian-fips-dev, 24-debian13-fips-dev, 24-fips-dev, 24.21-debian-fips-dev, 24.21-debian13-fips-dev, 24.21-fips-dev, 24.21.0-1-debian-fips-dev, 24.21.0-1-debian13-fips-dev, 24.21.0-1-fips-dev, 24.21.0-debian-fips-dev, 24.21.0-debian13-fips-dev, 24.21.0-fips-dev

Index digest:

sha256:278ab57620cd8a52b278504afea305cd9147da50379dad6c91cc1380c7098352

Manifest digest:

sha256:dba0591688fd01b3567ec50a3a4f11217b999adfd731438a06b3f130e4e9179a

Size

80.67 MB

Last pushed

9 hours ago

Vulnerabilities

0
4
6
3
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:57662f9d4da9bd3545a20e251105ee849b3b2b040b70407328912e3b2945f6c8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:6f8c5f0f68bb31fa370b24b8356c708d5b5d0ad11563f26a0866e10d4f1e61de
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:4f7fc4dbd1648b95616e7ff7ce55505d46e4394277b6183fa8f1473187274684
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:8f3cdd84300c7b6ff5402b6af68d98186bc7bc6f491fe738079bd009dda15329
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:04174cbc8371bf7b0b5826be4f25428a29b61f163664e2850e42e8245f26b275
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:2169a5333ee54feaff0066034b86f4361a2dda868aa8618f20d48c059c0334de
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:48a7549c14622399a3a66026654e7034bc1bb8bc6bce2985d71305e7e9e8617b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:d2d18fc59d06d1db35d70781d67dbe004116c8e3c8922c74e19bbe2db805635f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:2890447aa1e195b8171836ba1690205a5ee5ad04f242cb44f614324718be6ac5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:4d17b6338759aa7c2a672d15d8cdda532c49c62091dd4d418b9093fbb980cea1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:2ce9031a4f3ad2f3236cc8d3e740f47b05df1f68f763fbbde30f14c095981fb5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:f11b23efdc4045565dea6af9d609cccc439604b25cae0b08e7bb964f9b6a9d4e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:e5aee8cf8bf0b880bf507998e61ee95bbd166499d5af0a43024e25545ebf65f6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:ff4a28ea9ee8f10b035bba85ca394b4cad3ad5a68ca8f62c52465361c62a1721
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:e340c52e5cabd4977b09897223d187c8caa99df9e2789af7f1b56fd830ece0c8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:eb9cc827579cdcdfc3de00b222ab8d423faf7432a708421b2a2cf67a5dccdc88
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:e52815b51d4e808bc3803a2487aa1907ceda4eff22bd8446f699e3b82a21706a