Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
alpine 3.23
Tags:

22-alpine3.23-sfw-ent-dev, 22.23-alpine3.23-sfw-ent-dev, 22.23.2-alpine3.23-sfw-ent-dev

Index digest:

sha256:443977195e7b2ecdb4cebf1fdc042938f8aabf1273906a107c272c12fbc16161

Manifest digest:

sha256:a7825d6ae1a22eff874685d9936759fa4e94612565cf521073046b0ea508ace1

Size

87.69 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine3.23-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine3.23-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:bbd67392990f1191b22e9ff12bc5aa873073434b66810897a9a2dff19f0d8edd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:dd69690747dd30f621137abbe202b3665df014d73996997082a7c23c072e989b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:c81a6191062a6a072bc08576cc086fd080d8df6a552715b93abe9e0b6e872d3f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:646ffee4e60fc6b86a1d04effca5dbc6d6e37973111331b6f2e5c6bfb1149de4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:9ae35146e6bb6ae676bb3a5ef9c566ee6ad765e46a0303896328596a4dc41075
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:ee7c76cfaca05736650ad50b36ead202d8219be5b14e75e0e69d19a95b603560
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:5388cc01ba0f7b0ee90afe85acc3be857fa1fd1a7e4e1d52ee8c4fa212a83ece
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:93f2d851a212e5916821c29670de9c54443eeedf2fe7697e1a889d5589713726
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:8f968be89f06678a02f470f59303d64c252c1abdf1cb6d0361e82cb486a11744
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:8cf048e8f501849df24ba9c2e5c25383581d1251bad9ffc9051d9864287d6a30
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:82a02fc72b2b9f02ccc2b16d27edf6ba5c60d824a74cfc2ed850e5881f46405d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:267d94984b051162dad6cd9ef4631dfc5bb673e811abbfdbe0832dbcf41478b7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:7ce84df9e8144cc90dfb21db864f00035b98395e5b915b53ec6d132b4266fad1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:efdac6bbeb9570f438e9e9a92fd93930ce1f677ddb89cd2729c073faa42a83e6