Sign inSign up
Node.js

dhi.io/node

Node.js 24.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

24-debian-sfw-dev, 24-debian13-sfw-dev, 24-sfw-dev, 24.21-debian-sfw-dev, 24.21-debian13-sfw-dev, 24.21-sfw-dev, 24.21.0-0-debian-sfw-dev, 24.21.0-0-debian13-sfw-dev, 24.21.0-0-sfw-dev, 24.21.0-debian-sfw-dev, 24.21.0-debian13-sfw-dev, 24.21.0-sfw-dev

Index digest:

sha256:159ed97c84fdbbdf6f688e7f96d8e7178a4665a9863be2dcfa30d976f8bab04f

Manifest digest:

sha256:d7504e38c3f9d134780fa871b818560c3d7f2f2a6e1a6a57a6c91578d2f30fd7

Size

115.79 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:6b138f1eb625448ab55fcb7c7f693dd6a18f24cb82402208191b271b4f0ec4dd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:54ce76885e81fe05abc15ea48eadf1cd0a57e73e10d99055ff43989f9fa56e81
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:a1e057c8ff9dec1d59f381dbe1c12b32052e2ca9a5c4d144710743a79dcb0a67
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:28813731289de49897b914cfcaef12e052776e44ff6e99fa7e99e1517bfc97a7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:27c11740e625cf441150fc55cef697437be4e1486cde2b72111dc1a9e8997f18
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:6cff44af2d68271cba9c6a1d8329c016400a2bd5b7fac7b4882f9df96941d667
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:87369e2f8ac402d9b5b083b4731aafdf8e11621ccfeeb6e0ce754973bffeaab9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:b66ce8d54a5be320a71c32b3948e18ea85476e6c835400295e8d323b399f877d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:0eb02c4bdeb00d68427b489b8bda286f8ec6d126bbd36bb643a3f9e802e5cf51
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:e2455a9b63d87471b0ae7f8656c467e2739591921a106c086cfa6f607e659c68
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:e959c2fafe554b29923627ad92678c8216bda6101b157f02e2a277c147fa9344
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:13a33ae272a614db7997d44d4d47319298263ac30ffab3fb620cfdc8d11c5203
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:901a40240ccf1916c1b59039d6f68213447d9587aec0b234ce0763c9accafe2e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:924326131d90c592f99d46bec0b069c75dda0e5dba2eb0bc864b6a156f248a67
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:f7aa6d0d272c2a7f6aa73bc96b3311dcbf5b9525b22876c5cc0df957273dbf02