Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
alpine 3.23
Tags:

22-alpine3.23-sfw-ent-dev, 22.23-alpine3.23-sfw-ent-dev, 22.23.2-alpine3.23-sfw-ent-dev

Index digest:

sha256:fc34e5de7b3a235d9b9ae99fb4692806fad5a26ab4d395f0db595699fb4dd34c

Manifest digest:

sha256:5a4941bb2f107264ac72e5ba925b223fd2f857e9f8882c37d31f55a693bf8bef

Size

87.67 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine3.23-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine3.23-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:2c2dc11852f1921b22d16e5df49afa88f4030f541974dca56d2999a1ba66377e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:c29daec3e12e76ec3f1b4e738cd21c797cdf1defa5f76ef4a4052e42af41da44
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:31c8f8b3e37fd808cadc2f7239412477f2a4400cf2ff3b53a05f648dcde6c557
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:9da683539bffc9d712a58df318cab60c2de633919276806cc466e3fdf6ed0cd2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:8438079d365e2952ec0606824ebaf72cb64b2212ff9d2834f7e7841fc3801c52
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:2459193af1b35a10cc125631f8094b1b5d73130c76f56978acc72d710eb27c5c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:ad5c208f2983a115faa5ad997be78ddf19e8f0fb47f961765a184af33756c7e8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:725b269a85a51fceaf08f5f675da3292f6dd393f8626ddc307fe7728d3af07de
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:fd218139af69c0831fd72e88ecc28086f3050b155bf57650aad0c45f1c1ff674
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:e1cbe5712cb3d23e6fac25af040816961a52c774bdde00795ad3cedf37db7d33
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:f41ed90eb0f4d0dabae8d831b5feaafcba68e7462ef3eb4089dc7d2314d15c60
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:3095c17e03a0c5a049e2d1424546f5c44fb748be9662f48cc8f543308e140206
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:0a64141e5f6f98c754a299ec384b6b7177a7a422b37aae674afc56f8fa1d6a57
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:3d18942a77ec0d1d21490609fadba84bb150ba3dfaad1e6ecc70f74e8121e74d