Sign inSign up
Node.js

dhi.io/node

Node.js 26.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
alpine 3.23
Tags:

26-alpine3.23-sfw-ent-dev, 26.8-alpine3.23-sfw-ent-dev, 26.8.2-alpine3.23-sfw-ent-dev

Index digest:

sha256:2abea8aee8fa138455551c46db0a199e612b8ab39859f4b861635147054aa3bc

Manifest digest:

sha256:bebd08ae4d677fe089919817c8b80387a7b70003630f20f89e08dc6b4064146c

Size

90.84 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-alpine3.23-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-alpine3.23-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:5841938c4c27fe653707d2c1dbf0035491ba1616f5a0d7a1fec93fc2874c46cd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:94215d43b00620208d608c4d16dc9953a014516fbb8b88321bd483eafe191e78
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:32a94ab10ea421042902234a9e3afb88968ca2f7556cde9d1af2756cc086bc66
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:fd415a68cb793e32b1c8e1edf2f706a3d8f9a4d9c6255ad3f9d541dec2680586
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:ac11d97024eeb3f1ba6f509bfd5a75fd869cf1958b30365bfe0d071e0524276a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:5106fea4ca82796d2e56ee5ef7361ba77fe49a41d8dcd87a465c09dd4e26cf2b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:25b17cb5e8f64d2f4a53e3cc9d28009491cd969638d8abaa05162adebc5836d9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:359a98985b2d2d7c2dab2238d5de4c0ec4caeed58a79d0d146daeebdee7090d7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:55d6b0592f6cc4173df9dda86e0d6efe175dbac3cf09fe46bbc0382be9672305
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:dbda917e4ef1b81410fb8f83d1f11b38d561ad535974e486d33c3c9eefc31c2d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:a68fa9ff664bfaa1e11eff29275735777b4c636889eff428aad161976349313e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:ca6cca967049cf341a4276f75aee518d3131191ce691f8b0d2398c9dd0938be3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:fcbaf88d5581060e101a19ecca303a114ed1755c90ea9e63b46a4faabfcb0650
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:c19e576bcf0660b11802b84830489ca8922157483664cbcc002a4f7971aa001a