Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

22-alpine3.23-fips-dev, 22.23-alpine3.23-fips-dev, 22.23.2-alpine3.23-fips-dev

Index digest:

sha256:7730040be632862d437be733ff901972866c1bf8fe7b2fa08496aefbf70d2351

Manifest digest:

sha256:9d3099665c0bf03de16ad7f52ab6033e93a8228be2f25d3b0ef188c53be0c0d1

Size

47.53 MB

Last pushed

1 day ago

Vulnerabilities

0
0
1
2
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:547d0474ccbe628ad2e79d39eefbbaa43db1b1a874d4b0e2cceae6e3466f0183
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:b89f963d6109938947d8a2a483621716bfbcdb68f3d4462aa7aaa3dc4345f89d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:c1485749a0e464af21766f107dc679a8f13dfd37849388cd51fe2877bf841790
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:f816d60d11994e1b653981a712361e90c0faadc92294710cd91727c0c66b170e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:aea678e529771c42d7f3d0bc7ae408c963ff4f269306fe8acdb4847a98ebc58c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:55825af92e04c56dbb796059ca50aabec0293b57380ddbbf5da1b58807ad199b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:3e39e436a52888e6229907948ecfadb30b04f6ed5326bdbc3d1a81868ac70779
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:a88b683da3f813df7d7274bbcab52f2d5d20052c5f131e8ef8416d2c23256ade
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:08e1653600b80963687b6cbebc592e0ab0162fee58195a5292fc984d92b1245a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:0b48cfe45c948eedd367d2a03b20c106ec10d49281b251dc5dc003a85bc56f48
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:7e51dde336507217811d839180700e3de70949d8fa577ae5c7e92227340ac0fa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:4346c0aaf515a4428a6e96243df0818db71b9d5f4dc77c074ef3ca5dc04ff0c8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:7cfbc90179eb00d0b91bb12a5abb5777ad0cfa7013f170d922c713dde36b70f2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:86877c56ffe1c58c207bc65d5e7c9318d9db55c24e9be467455045a8227ef6e8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:37c487035c81f1900b4557c465aed899297b77816dab291b3297b6ac253505bf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:7a332b82c57f4aee0423bd30eda5a75e832549756d6da691a407402d19d62cc7