Sign inSign up
Node.js

dhi.io/node

Node.js 26.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

26-alpine-fips, 26-alpine3.24-fips, 26.10-alpine-fips, 26.10-alpine3.24-fips, 26.10.0-alpine-fips, 26.10.0-alpine3.24-fips

Index digest:

sha256:0c71af1db27705693e8e2aee654d40e1e874872aebb31f017b0833a321bbf2d8

Manifest digest:

sha256:bd0d678d8e50a78e46d59eae0bdaba154a287a34e22eb4eff79e0c3f401fc7c2

Size

42.17 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:a79f535f04ec922d3b5eae611ae54a39f490517e25e4381f8d11fe8a1c67e096
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:f89b119e08241b33fb562a3cf6ac56218c123230c34ed74aaf4b936ea6f246bb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:047e4b1d6a6e301b4e64945fafb62bf60726cd726383490c628fdc420d0fc569
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:640ec58dbc7d3e4789e6504c9646986091cd9c0f47d7d8ff5c7f0a4fd553298d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:d0d95796936be24f2c59353e7a301adfe2ef9018baa9e6983679ed3ac3828528
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:867445ab2d5ca5d5ea7ec040106bc6f4eca5a3b110e85fcb4bf87c74db602dec
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:ad3fbca92a3f370098a4c06c65d4817d680714db4c7d7ef591efc0786380cd37
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:de00f1f961e413c5d310cef5d9c4724ce6f0760657d7f239c7c026104ab837e7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:86a2fe9cfd8e9290a6ea5fc27cc65c549291e419b6076a212c261f7b629d2e8b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:3a1495d7a65e2606bf872d0e37bb2b1d5d1303619bac74d6fb66dc558ec55314
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:6e93f08f1a2e60c3765e7674c7db169b517507aa51ad8f637ab939c6189e812d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:357539af611a2a982036991fb91aba4c4126447d43a9518c4417c15bd40bd59c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:94526ac6748d4de077f1e3189c843d882f47f9b718954c1e870a1764bc53d714
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:5f44e68f4903c047517348ec87d91f4fb44f6e848646950e64890c86bb707bb8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:624265bc55fd66beb5ca703c3f4d9b66a1f57d345cc57a2826ecca9d12ba1cfe
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:9e1e05ed411afa76d26c6816a9db756843325984d2f8fb1a2a2d866e49207926