Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

22-alpine-fips-dev, 22-alpine3.24-fips-dev, 22.23-alpine-fips-dev, 22.23-alpine3.24-fips-dev, 22.23.2-alpine-fips-dev, 22.23.2-alpine3.24-fips-dev

Index digest:

sha256:9aed68c6023e368dd9dd7bc030881196af65b2ad37cfb5cfa0748abb480c7958

Manifest digest:

sha256:725355419d353c9a8bca53fb016256735f342f088476e50a4d9ebfc49535a0f6

Size

47.56 MB

Last pushed

16 days ago

Vulnerabilities

0
0
1
2
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:420983d02d7d8230a38ab58520118264dabca510502adaa5f0203250007850d9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:0c304986fb8967a49f5cefcc6db3d725210d2f821f8c4ff26afcac17dff80886
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:08bc66034736fc6802a68c6f074ae91cc69012f90538b77d2e69fe45474327c4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:1edd3473115e682dd54d6b4d66ab894cb80f3a65bdd432d5780fdeda46599f97
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:66bcdb9509437aee48fda74369a662c9f0292911b2ffb202ef3880afaca89004
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:f98887780f785489cb5228776f3255fb1fd7945f6a4287dc8cbbf6fc47145840
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:b0a3f0708a6a485de0121565208d91dbd57aa2ee18f4753b5abfaa8d60c56120
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:28c2922f6af8ad475f39dc78b37e74ed6a21be3662a42058f855dc68a0058c6c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:73ac2acf7174321ea7268b795b7ba0b9570f5eb9a8cffd6d91424a002b2a37f3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:5ebbe56fb367907cfd7f1413bcf7b0db42265258c4bbfbb72c9cb3c4d2099609
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:5d091775caeae1f33182b510e927f995d19ec98a6070dac60dec314d30acb094
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:78f62bd988a11b0f0c70977124d342b088be3fb617cc28c928f4ea2812f95c78
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:64422a51d8420b4ae05610dfd85681930f075c987a0ba6c2a8142aec3e1a8e37
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:24bd9742ce7ddabac8b5a4c9aed7e0687eeabd5eb6e95fd9465a3fae55a2aa12
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:4f196e436a40e1589aae8827abb984a6626e2da042b0786360ec3264a49787a2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:e55f81a4416e1d60020db7d3c2367d4a911c893fff893cf648c31a2510d3674c