Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

22-alpine-dev, 22-alpine3.24-dev, 22.23-alpine-dev, 22.23-alpine3.24-dev, 22.23.2-alpine-dev, 22.23.2-alpine3.24-dev

Index digest:

sha256:884fa94e9c3228138eeaa7376f40972647ac6eaf8c960e407b1ea374f9479b0d

Manifest digest:

sha256:dae0a2391e287b75eac766f4097a9445a56b2f279239dc4c6b02661259e7517c

Size

46.42 MB

Last pushed

13 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:aaa1487fd98f5edcff9a3da7f4ecca4a9ba65d170a61c1def66c7711d64bd802
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:c45933bcd25e5c33031bad07c67c532bf4dc661cc4fffecc3bfedffaf6958d7b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:91407e4d1ae506b5c178313d496a309fbd9cf0f0cf5b0a3a5588a83d61e63df0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:ca1e8abbd534fa0f5ab0b5a85081fe863deb79405f3592bc9f77288826cbb020
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:7389804ad0ee14af128893bb956399ac601661df77dc3de6118b45540342eba5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:2cbfe8131410f1271d631463d180df1e54610668db137f3ea7a10e3d03e6d821
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:791bd264724e16a0185c27b14fb596a38f4ffd8a007bbbf3313471d60bace02f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:c6a48da3c699464281a7e6e5f87110aa1564013e59531f4e1c158fd090b0314e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:e3b5cfc21814414501a691acb84ae82af08be40bda33dbb48e7e0f2bf821b73d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:bf823896441797caa02998deabf106a3565ea170924b9bf9a0475717d3faa2ca
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:410931675b99f23e64cbf19fa6683bd5d98d316b5df338b9dc6265a54c8b4cce
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:f424eeac585d667c66334a7e6a83663caae81bca8557cadd68ae48a813d08080
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:16fd33c110cec7b6cc39aaa12e96d3af9004d2596995261d14f725057fed99d8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:6464b55509d54969129e83889854587a73cff311404de7d5859316a621679624