Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

22-debian-sfw-dev, 22-debian13-sfw-dev, 22-sfw-dev, 22.23-debian-sfw-dev, 22.23-debian13-sfw-dev, 22.23-sfw-dev, 22.23.2-1-debian-sfw-dev, 22.23.2-1-debian13-sfw-dev, 22.23.2-1-sfw-dev, 22.23.2-debian-sfw-dev, 22.23.2-debian13-sfw-dev, 22.23.2-sfw-dev

Index digest:

sha256:c874973a9dad2408272d7c00dc74eb9115882ed8f8e0d2397637891e2d17f4c1

Manifest digest:

sha256:3e4486252f62eb88adfd5a6e1e57845491463f4580297e9cf793ccf2cb743eae

Size

115.59 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:f4e0560073581bbfd051c8cc6d91d3bcb145cc1f070056f865d6904b33db2e36
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:cfec846b6854d70d5bd19c1c8817a65b6dc091164a0201fb2797b6032954d78a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:b6ac0302c04556eb0796b113e4d680aa8aa74947f408f67fbb279ec839bef52b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:e8780a0a611a1531b410ff319d08d7a09d1ec84ef26a4e4a0d9abac97d0008ae
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:78887c038ef5abb15c396caade78397709f67662fe5d4de60c99f7b8d9494d7e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:2b1444e8c15c19538d6847a1a4b5c005730c8fca006627a1e0c7aeba6f1f35cd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:a55d23770c2a45542e1e386c8daa3a32a3b1d2de336a98166fe7bc1f68875957
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:5841ba83b98f0acf6740f08c8dac59a3c276dcb340de289b133034b69e1f3886
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:b4101d6baab02d734216dd8f81ea55c39e57921ca4c246cc570967c0854be8da
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:92499acf86f94aafa2deb9afbe94093b5d45321894c75f4b4ba3e15b783f6cc8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:94a226015655b203b7204574c7c7455c9173e1a09a6d4d143a80be6827361224
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:f8230396be02e561126dce3f8c9d4375cc40d738056691c7f9b3a61466c10cb1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:acd7ddea381033418746bc83116493e3d9f7892eb88ef0d80229ffdbfa4d782a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:71f9e0377ed5cf00275f5d6d68cdcc83cabd8c182f11f3f2d5162569cdee0497
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:0d4480c52274f425f246bf1094a1da271c79cef212bff4b71d98c7f32f2a469f