Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

22-alpine3.23-dev, 22.23-alpine3.23-dev, 22.23.2-alpine3.23-dev

Index digest:

sha256:95cd582b2a532b39b3779441ba70ba13726b86a9676089d48c32d693ff67d056

Manifest digest:

sha256:5319fecf2afa0c0b4e561e7339efb75e6db212d6203c59ebda8caad10ad63fc7

Size

46.41 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
2
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:8accc397fcb873d8f3a0d7d6f828a9b0968e89c2290777bb29bc36c7ab65c50a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:82ba8f56dad7856b8d01bcdd6331d0a7b481935838ef8c389303b885dcf8d48f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:5b688c1cb03a7e031cda99ba96d95422233cdefdcbd74473a3d32b348e9ea4bd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:03e5a75e699872a01f58751190f4278c7f1a150818f4c156ad9b74e4e4e57680
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:6c7715ba32b77c0a7b6e6ae6e78a229d1f18d669b75afd67444b6f91329c57d2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:ae4ee94af20f7d8c83eecf6692bed13f3806ad524c27c14c9db4d0d572f723f1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:1b6104cdc4bee5e59c5689e767ceb30274e1777bac8a91b54b4829e8fd33a910
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:1a681d2ae6a000f765f608204a398ca17c311b2da6373522c8ce113c9fcdc522
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:25d4f4cdf4e9874f0a381c3b576e48e5147f8415a94a3ff19cf5d77a08ef99cd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:f20057ba453f5861ff9b8b4c66bfc972b17caa0813a36a7fb7af388d0075145c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:ddd8f96f4241173d2ea2ede52172c9e2b6bdf4d45a246513b11cf4c222a9deee
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:02b5f130b64a6a0c9427ae656f5c0d38ca96d807f7db49eeb0461a900eb5989a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:9f45d130d1043c0675f5f7b18d528b07cb6baa94b9604cc105d39dcc689148db
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:a050937e8e664a108c14c678087c67a2b3a5540d25284187c9eb86b76275c49a