Sign inSign up
Node.js

dhi.io/node

Node.js 26.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

26-debian-sfw-dev, 26-debian13-sfw-dev, 26-sfw-dev, 26.10-debian-sfw-dev, 26.10-debian13-sfw-dev, 26.10-sfw-dev, 26.10.0-0-debian-sfw-dev, 26.10.0-0-debian13-sfw-dev, 26.10.0-0-sfw-dev, 26.10.0-debian-sfw-dev, 26.10.0-debian13-sfw-dev, 26.10.0-sfw-dev

Index digest:

sha256:a3fa70ed0beab36c8159879b960b794e89a0893380956e1f038a5eb943cbc7f4

Manifest digest:

sha256:7658e134419a23ef7f7a15c36371dfd4afae13860314e07cadc675e1b05de57c

Size

118.31 MB

Last pushed

9 hours ago

Vulnerabilities

0
4
6
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:ee4f2badada2bbc235f13c0fdea7ebddb1b95a888fc3d55aa29c162c8dd71ff2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:323f5bb5e93f3da2015d6afcdbabc55269b7fa353ecb8785fd544c8226ed3d80
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:eb6d5315ae2ccffd21baae1c7fe36e85aa29c133f9cd051eaad0b048216eecff
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:fac67daf2709af861ab6b31ad7fe6990a60f4b44fef86c25f6650b561961d0df
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:ed5c3aea5ea4c690fd1bc844c8efd0713573dd845ca6d716be8ecdf666b7c974
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:7df3712de08bba2bae9c902e737a0444bbe3835a50c0daa2f08a8c2030c9ac4f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:d04d3b86705b0eb51b1f39c49aebaf00c87a366a60b1e661e24e25472acff794
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:5138f78b9a28c83a26b7ce6bf1c70d92499be9bfcb0ff0b965210d40f8e18672
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:e10a35ea5aefe830c3c9447917faf4f468eb9dc1657162847250385092a1cea5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:55a8ae82b3d62cfa23a9b7b990ff87eab0bcdcfeee0dd561c11fc4445dd83145
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:437d73215cabd91ebb84eb74b593b073603e6c155e7b49fad58a376807206cc7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:13df33c7a0adee824ed2510f539199252c767842ff6e2f7c19f297060c44ce58
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:045b8bf63d39ebe62fc5a3bb07bc71ce0e8f5b8700ae8df58e43d0f11fb503df
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:c8e1b51658f4282d5c71ebb2f07929cce61e1c16a61730180af046b22d762134
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:4127b3a3144efa61a9bfd664159e4a585213eb5310897d30f9b9566e4e65f0c5