Sign inSign up
Node.js

dhi.io/node

Node.js 26.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
alpine 3.23
Tags:

26-alpine3.23-sfw-ent-dev, 26.9-alpine3.23-sfw-ent-dev, 26.9.0-alpine3.23-sfw-ent-dev

Index digest:

sha256:41ea17282af023d674e4f08d2eb626ced74627ebfa65c5f950c67b1de7b1c0d7

Manifest digest:

sha256:32529e6be59dc868df46a318eff4bb63dd8f4021c23ac131ee6a6c4f6259adc1

Size

91.06 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-alpine3.23-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-alpine3.23-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:fd19be22a506bedc747104a63d25db6728b671205f7c4d7e773acbb77595accc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:fb44d167b52ba9ea06196ac4430ed1668bd1719fb306e25dfd8739c40eea46c4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:d4796a6b2556314ca106773616b83f3b78af4922e74eda52c0f33c2c30e6f3eb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:03f8619193bd3fb546eb21d434c2877714da86eaa978c60a25edebd17d91daa4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:037fb2c72f2a13f2a81ea33ae61c42a8ffdcd9c89743d968d0fe1e133abeadcf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:a73ec6a8a80fd9f5a83483cf612552d1807754681c69caa64ba9eef5d8750fb4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:102ae75b7b3f1f138d38f0bbe74280ba7be64c1ff7fc86403196d74a7565be62
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:bf5d0f19abca58c409685085b85c5fcf26a91e6f39fd2f0926fb1b2575edc2f1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:63798701ae9c63bd80b996c96c6c5b628a4983bd504b3b534c7cd653602ef504
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:2ecd7f65a2364f275611000cba90087696825c351f2eac9ab71b431934a602f5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:5e23e47d27a4a7f29368a17d0c62a4562779774e4d0cd55eda960c85a67a5cc8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:d62df84a565c4d4f62f456b207d8d0216b1f04fc6f71994e52a3e9dac0184bef
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:d510e4f72ab1f41f57f6c92e3d4b321298c389f066b4f7d2a4406dfe0085e96b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:87372fe01de201072cb150750559cc77bf2fcc15ac0e2d3e824e98f2d438d8fb