Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (dev)

CIS
linux/amd64
debian 13
Tags:

22-debian-dev, 22-debian13-dev, 22-dev, 22.23-debian-dev, 22.23-debian13-dev, 22.23-dev, 22.23.2-0-debian-dev, 22.23.2-0-debian13-dev, 22.23.2-0-dev, 22.23.2-debian-dev, 22.23.2-debian13-dev, 22.23.2-dev

Index digest:

sha256:37bb1c80fd1201bd959bb7e2dfab0c0fb02b66998e19ca23ce6ae19fe95235da

Manifest digest:

sha256:8181e2a255b759a00c84a6b778b8fdf89261247e65f0809db2cf5846c75475da

Size

79.68 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
2
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:7140c4173b5592c802b9bb9966aec37795caf9c9166406c997c190fe4009a139
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:1b4ae761a213ca026e124c718b62964540f5bbf765f370b6a17e960b914332b3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:48bd942de92c6fdd58e304832e8b833c15f39fa37af1f16646d2a3366f8f73af
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:3ab5c2241a73692d93be21c6ac2bbc16caede66e4843deba2108d8d42ce8d2ce
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:cebf8ec58634a3b09cb76dfcf0ae332abfc813b3d999f838526d39ad440b360c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:fcc94090ab8ed3230d2175ab37e9cf68bafc12e14eb4768e9f8c0bb2d97bbc92
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:e17917f7a20c39d6c5525b9dae4e0f01decd3eefadd0ef16eebbf5a627d269cc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:8024d3858794313fed32b3dc50f21a6ba5e59f43930ddbd1d208764dd0e7c8cc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:f9f74f2f55c097f8dc87c294afabe6e95f2d2087c36d9ea879b9c57d92665bfc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:c6dbd903bf5a217007878a614f2e835d9a631ee25be9938f2ebdbbeded92651a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:d78ce0305c7462f7b6518db86c2eb90763212ed199fb19a9887ed7a08287d9cb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:f4a2e82b04ace42ff8a11b3bd7efd32d11deabf986d95e2a7134a6d0fef04b85
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:e2e3e00faa0bdbd65e5b40de1d4b08bffcd2b426933b13c15335a90a6c0997ef
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:c46f688dd348219dbe85f1b9197477547368c9ce59c8dc2d143954dfc8def756
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:c0ad73be97483a9f5983e8d9ef8cbae36608ace3aab82df12919a97eb7426a2e