Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (dev)

CIS
linux/amd64
debian 13
Tags:

22-debian-dev, 22-debian13-dev, 22-dev, 22.23-debian-dev, 22.23-debian13-dev, 22.23-dev, 22.23.2-1-debian-dev, 22.23.2-1-debian13-dev, 22.23.2-1-dev, 22.23.2-debian-dev, 22.23.2-debian13-dev, 22.23.2-dev

Index digest:

sha256:178fd7e345531aa16db11c80b087b8ea566cd01bd7c226444736e2d23608c56e

Manifest digest:

sha256:7dee5b3d63ca4dcaa7266eb0bf3dddc5c85ab2b8e623a0e89bcff7f7ba82a947

Size

79.67 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
3
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:67f56df8b7954326a1a54e517e1cccaa8f05891890a02635606ed6c9e8b208bc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:c120790f291004bf349f3a6bde37210342a3d899c4627f5bdfa5be00fdaf12cb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:2c07172b124d0279f752e2a064291ea4c0b67ed680fa03ae3430cad637aa7c5c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:b7a7c3b852727bbd858447600b7b710f2b4dd563ed1ee91d2ccae53fe5f36863
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:aeb09643279ea5b99dd604d24253884d18fb55c87d97f3b67e65abdf2a25e8ce
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:ef73f2cf6e50ad612198354badf9037a760a6cb4271788c20b9237d98ba2e7cb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:269ae7f64d44ba52cadf13d105179ca49efbdcd71953e425346f1b420838dd35
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:a50d7cd0f98a5f169eb9e307e8aad5cdeddd41e472e2c8b38458f0b532f099cc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:db9636ca9036a86d25b6529ae4b0761e34927f7284be3bab0a3687e39a29ad48
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:955329a8f9a0769cbb8ad7ee006ba9382fe4bdf40a45f550cbdf47a54e560c30
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:84c8ca2434082a4eafad488ae9480629996c33d9c16f83f635219a6c7023514b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:a4ddb99918aab830992d5ae795a521517240f179a39c0d4b0945a8089416abc5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:72e1edf6def3338dcefdd9a2ad968d56e41ca4d6d69124763b64698a8ebd0f1f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:dab809e86b636c05e907d92e1290242fa80bc72030967e923d198b3acee2f985
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:abd4ad24c8c0d741d31079c47ded3111b9e00d058140d20f7935a82792dc8b3d