Sign inSign up
Node.js

dhi.io/node

Node.js 26.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
alpine 3.23
Tags:

26-alpine3.23-sfw-ent-dev, 26.9-alpine3.23-sfw-ent-dev, 26.9.0-alpine3.23-sfw-ent-dev

Index digest:

sha256:125461e9fb85d60ec2f371bc5d196980b27f8ce549137a62f5ef268f866b2dbf

Manifest digest:

sha256:77e29f2ca6cf3a04bebaa43dc046f67aab9fb307ac131bd2023d20c59db40966

Size

91.07 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-alpine3.23-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-alpine3.23-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:935a297c10d0aa51129a94026beebdde489e834755531d42dafe75ed7765d058
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:a059f99a766cf652111f02795b9adc2ebfe8ace741f6b70a0a6bd6df1ee49bbc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:71940d92e722594c96a82c88087d4f37dbbb2eb92d197b3cee307d83d19bb6e8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:8d6a29406ba3f478767d0d4bd5c748cd157d6ea3ae3de8477da81b73bda53589
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:13ce7214f98da8787e82306d7ca471d01eee28b6bcf8068c931a70c5fb4e6be2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:29e166ecd11b4a9d8c55bb20afa81bd19016bff2cf53d04e7d3b653ef2184f9d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:51483ea1d36558087bb7ca53479337df76bc87194280b5da2bb56315f55ede3c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:bdf31484e0ce5e3ed3032076a885f204bfb7d393fa1f39b97884a462bfb0c174
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:23af6d6fe383d9b089d5eefffb5c53130a24dc9bcf2ba6642b347bdbf45043d5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:86e447eed64eb6a37e0fd53031fb8eff92dd09d733fe0fb0c825a1cd2bc7f905
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:5a2875dde81e432a92e2b0c3cf40d1a21c9de8184afef155ed41a56a50424e13
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:d6233c480b42bf49d632023ef986c8398499959bcc15e87150b4cf10fa5ad152
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:56755ae408baf4ffaf921d363d46bf163dc49062c15a60013de5fda6c4d607cb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:ef01c2209d16437a4a0839caa3e77ebbdf7ba6320e20a34485b50fad195257f4