Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (dev)

CIS
linux/amd64
debian 13
Tags:

22-debian-dev, 22-debian13-dev, 22-dev, 22.23-debian-dev, 22.23-debian13-dev, 22.23-dev, 22.23.2-1-debian-dev, 22.23.2-1-debian13-dev, 22.23.2-1-dev, 22.23.2-debian-dev, 22.23.2-debian13-dev, 22.23.2-dev

Index digest:

sha256:e30815ffcc920673d31a186301c1f577974d24d701a16d8a0a9898a0c1e327d8

Manifest digest:

sha256:7f0e5a070b45c268627d0eff9855d2edef2efe6b32a7c7947bd1b03d00216efa

Size

79.68 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:af27ac19c12fd273b2900977c2a097e8e9d0f14a62527a3a61ac7b20cf567795
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:81a0c92c7c00cffe2771e66091dc448a56de1376065869af09c1697d82ccccdc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:cd4a2bf9e2d422b86212db29610044617af993118d2e1d2f8b298414198903de
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:21f723554d3ce4d0df58378cd3a11c559cb0c943d6b7b7d2c20cf1a3d3ca234a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:b5152ded680083b9475e13f8ed50e058efa7ec5c446b395857e5a06600d874b4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:9ce2d80276b321a060effd0e2ee0ee0982e489fea4b0763c68c0bb97a6f9ff19
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:2f940a25a04f487c8213727f680673b30f4973a61040a4857b5105a3fa266796
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:fb5d4a5fd7233b7ec6b71ddc41b5de4533879c474371e996b223c709cdc34fc4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:6300db2914d9bcd8a852217f2bb31b7f2af3779f2a54469adde45d1138c9c2cb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:c187e97c91b38c69eb65893e50fc449287afef3cdb634dff8b82c1e045c542a6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:b702640550cbd1523144b5fb1d0323f84fefa9b7cd6733be40da0b5c429f52b3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:ea3f4857ea86c825411c2c2425e0e6237f9d9b9cdf67a4fed085f45730120210
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:1c0e7d5543161ada35b3288e499d09134ea7159f941199534e8ab3e29ea9579f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:5c5478b07f3907664c3dc694a59a0412ba34e355a456585f114e84656b53a6e6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:b0177cfbfc2ef03aec756523d5a9604076210ca009c95a6ed4794617b781b61d