Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/arm64
alpine 3.23
Tags:

22-alpine3.23-sfw-ent-dev, 22.23-alpine3.23-sfw-ent-dev, 22.23.2-alpine3.23-sfw-ent-dev

Index digest:

sha256:fc34e5de7b3a235d9b9ae99fb4692806fad5a26ab4d395f0db595699fb4dd34c

Manifest digest:

sha256:15fc47c9fb8cb1673150e028f21ed655fab442d99db82c674541bc5abaab3392

Size

87.01 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine3.23-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine3.23-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:65caa4ae9fdbd9b2794c8b964c5592bbcc45f7591d50b6c058b61f339f3aaf96
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:5c029e565a27636825701acd997cd42b7c9619f016526aa54d53a79ba80a21f0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:a1b1047c9fddc8d135519845b89f18c55f3498f38ebcf512ea2ac2a901c278bf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:25285a55c71afc5ef4955e6147fa7418048d0d263f4694f1580480d2032f4b46
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:bb48726374bdeddc87754bbd9365d49d61d0ed9f6475ceb22fa33ce7bfb91e1a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:ae93d3dfa119cbeba28e49d2a1d9a1a2cb0b61f963708607d4cdd36b474df1ae
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:d6dfe8ec74472812a38bb2ba49213b616d74a3be1ee96650968722c1a05feb5b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:96ed8e82b78d1fd83050f82884794f70dc883c0365a345beca84aa76dd43a61d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:c81d9aea5d2f1abc7ceb13e53053f0b6fa3e66c433712ef431f9f8df71803394
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:f4a4c66fcf6ee7c6626682d34574a35098c9db8d3efa6d07b49758f032c1bf52
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:924a5c34a57f129728ee75b1383cef39bcbef997531562a90e70fce0669a3f90
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:baae500547ec023b71b1d5d50e58093ba7416cc13b951fc7a879c7048402cf29
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:a0c7836116b8cc730f10482db39b7a9c0613c92b45e8bf787df3df2706083db6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:fc92a9371e782f60acd93f2af60d868a4c7e473659d62d3c10c7acc58bf96aa2