Sign inSign up
Node.js

dhi.io/node

Node.js 26.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

26-alpine-fips-dev, 26-alpine3.24-fips-dev, 26.9-alpine-fips-dev, 26.9-alpine3.24-fips-dev, 26.9.0-alpine-fips-dev, 26.9.0-alpine3.24-fips-dev

Index digest:

sha256:7cf9137e075d80f8bc9e9b0790dcf31a19b0e1b67f04bb7465a8dd037db27d15

Manifest digest:

sha256:13238d945d7a41cf983a8dff8ddf10a8a78eb98dc3dccde734662578a41ac06a

Size

51.00 MB

Last pushed

40 minutes ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:4363c8e56f5fe9c2589cb462a31fb5beefb8c78ced95ea851d0e263727e623ad
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:354629ab018796dabdd7752dd7a979b6f5757c8a09c3a79f853ee4ea8381094e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:2019e5bd8877c56488e69ec2c19c16d989efe2964b01ad841052c8007cbddf2a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:001f23de592572905124d5f8c7d941c6e2c2dc82e7b09f15053c8c8f36683006
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:82cf90a84086b040e4db2940591e8253a296ecf3519f679da0de05af8cb46711
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:4063391dfe4ebe1739f9389bd3f5a5b71dd635583d93ac6d7b10b55a2a135687
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:1d246536b7eb3ccf91e0aa362c6dd298f919b38278e4a51304277d6380d3c121
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:286f6ddca3c9835839516cc5deaeba4ae96fd1b863e52f4b617b4821fae497b1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:0f5623614cad3b47f8c339ab43f8806c72aeca2a92b68354d0fde7f0f027ec2e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:22303cb8fb86e73739db9718d0c407e67d19e558fd7c99cfb6c83ba6f5b997a7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:ced67b94abae925e4ed1453d0d519a8c23a551533cf80b960fa5835889a5cd08
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:7755ecc5f42f360e6d06d519dd959c128890a795f77f1288a2272b0a58a62de3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:9df6f4242b174b9291d667acfe7f36f51b21e0d53183a7663d9ea83c7637c02b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:72144cc3ebaeafb619660359396af8faacde5c556cb4d3a73c8199e676ff64d0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:763bc98826e708862609974368a54b950629dd5dab5318893776ebe2dc010bab
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:ed38ad9bc921512b02bf631c3743b5c4f4ff3d53bb5465b219e26881c8988324
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:17fff80edc0b7cd7296338125db38bc3c06a419dca7deded84f50d768c7b9ffc