Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

22-debian-sfw-dev, 22-debian13-sfw-dev, 22-sfw-dev, 22.23-debian-sfw-dev, 22.23-debian13-sfw-dev, 22.23-sfw-dev, 22.23.2-1-debian-sfw-dev, 22.23.2-1-debian13-sfw-dev, 22.23.2-1-sfw-dev, 22.23.2-debian-sfw-dev, 22.23.2-debian13-sfw-dev, 22.23.2-sfw-dev

Index digest:

sha256:193e77bcd8c2de3f94e23a6421a174295bd32f7adc51517a0df20b10e92f17ae

Manifest digest:

sha256:45afcfc30c314d7472eb7afa5536fc5dc00fe4f68b23799acba1231a0751841a

Size

115.55 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
2
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:601f96ef005188ad7862d65404b2b259c206d9fc7fce2f8352ddfa4a81eb2c72
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:f8cbd32f5c22a95e4d9ad4a70330b1ea9326aaf0675942d97b2cbd3721494b2a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:06c028961c64cacafd0a1fd684392eb6c926ea7f1c0cba534f5eb1e144a19b33
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:5830ab87c05b70f04e5e9aa09f10aa974a562e84325aa1e82e5de31cc5f9c9a3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:1e6eb606801718a3a3abaa35e47499f391481cdbbb1763c1beeaf7b5ab89baf1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:ba636c4364e5efb8bdad3f152cf5e20b295782224591e0d3b4352dbb188f47db
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:cf139c51e91a8cf7d7c21210a3b2183573bb607e0b3b3d233b565cbd1172b94d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:b416067d5d5ad71167aa84b5a5a8f50098c816a08433f187b4b03871404258c5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:b3de633ec1c2e5df38206560ac2b60fe2c21119213a5a98e351e505ff9f0fa29
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:1020033295b3ebcbfbe062cb2ec2f2c90c0100fdd9deb942f62e882ffdc42048
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:12742d4f166e7d126569877367dc0b102c1c7a0e8ad30a09acca6a022d4dc609
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:2415b4188e4a6a2995587f7a8745ab702b5754ad20ba7ddb5e7e91b176c12eb4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:bb5df382848bf4c86fd6458d82f370b20ad62331242fa6d03003d03043ae16c6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:c4d38a3706db5c71cf85959b68015db62f2cf26579fbc36426e740b0e5ffc705
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:ac7d641b543e86dc781f9a64186b91bb40624c930122631c9c1fa170a02d7dec