dhi.io/node
26-alpine-fips, 26-alpine3.24-fips, 26.10-alpine-fips, 26.10-alpine3.24-fips, 26.10.0-alpine-fips, 26.10.0-alpine3.24-fips
sha256:0c71af1db27705693e8e2aee654d40e1e874872aebb31f017b0833a321bbf2d8
Manifest digest:sha256:bd0d678d8e50a78e46d59eae0bdaba154a287a34e22eb4eff79e0c3f401fc7c2
Size
42.17 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/node:26-alpine-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/node:26-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/node@sha256:a79f535f04ec922d3b5eae611ae54a39f490517e25e4381f8d11fe8a1c67e096 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/node@sha256:f89b119e08241b33fb562a3cf6ac56218c123230c34ed74aaf4b936ea6f246bb |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/node@sha256:047e4b1d6a6e301b4e64945fafb62bf60726cd726383490c628fdc420d0fc569 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/node@sha256:640ec58dbc7d3e4789e6504c9646986091cd9c0f47d7d8ff5c7f0a4fd553298d |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/node@sha256:d0d95796936be24f2c59353e7a301adfe2ef9018baa9e6983679ed3ac3828528 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/node@sha256:867445ab2d5ca5d5ea7ec040106bc6f4eca5a3b110e85fcb4bf87c74db602dec |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/node@sha256:ad3fbca92a3f370098a4c06c65d4817d680714db4c7d7ef591efc0786380cd37 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/node@sha256:de00f1f961e413c5d310cef5d9c4724ce6f0760657d7f239c7c026104ab837e7 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/node@sha256:86a2fe9cfd8e9290a6ea5fc27cc65c549291e419b6076a212c261f7b629d2e8b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/node@sha256:3a1495d7a65e2606bf872d0e37bb2b1d5d1303619bac74d6fb66dc558ec55314 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/node@sha256:6e93f08f1a2e60c3765e7674c7db169b517507aa51ad8f637ab939c6189e812d |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/node@sha256:357539af611a2a982036991fb91aba4c4126447d43a9518c4417c15bd40bd59c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/node@sha256:94526ac6748d4de077f1e3189c843d882f47f9b718954c1e870a1764bc53d714 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/node@sha256:5f44e68f4903c047517348ec87d91f4fb44f6e848646950e64890c86bb707bb8 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/node@sha256:624265bc55fd66beb5ca703c3f4d9b66a1f57d345cc57a2826ecca9d12ba1cfe |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/node@sha256:9e1e05ed411afa76d26c6816a9db756843325984d2f8fb1a2a2d866e49207926 |