Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

22-debian-fips-dev, 22-debian13-fips-dev, 22-fips-dev, 22.23-debian-fips-dev, 22.23-debian13-fips-dev, 22.23-fips-dev, 22.23.2-1-debian-fips-dev, 22.23.2-1-debian13-fips-dev, 22.23.2-1-fips-dev, 22.23.2-debian-fips-dev, 22.23.2-debian13-fips-dev, 22.23.2-fips-dev

Index digest:

sha256:425456c58c626ac23423fcfda6aa494f7aeca1f77fea61fa9364af5cef380d8f

Manifest digest:

sha256:49538e866e3628ce78e696b5eb4629a60d0a75a74e190939063e90ca9a8f5605

Size

80.47 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:4bcf99c19033b680ea37f02bbaeb7e6b785d55382e36ccc35fe0417729b55566
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:afc857e8abedf97f90757f443acf007bd02d3fc9604c1b8970f95c96a78f759f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:83eee7c80c76e0c177d0f5ae9ca51dbaf30f31a1f68ecc4cdc55c13ec688b6d8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:109689f95b9f040b948f517ebeb07a0c1d2151e2bbef396b4e6576a96505a057
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:92704b30e3c3b07c27a28398c93a3dc78989f8599f739a5f10bd87dfc859f6a1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:8a2c1ba34f130730c6243e70ca344201145e5630f458d2295d4655b35fa21115
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:02f8ddf6c10246e33ff6d04932bd14447f09f84ef575c898b7df8bb814b36d44
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:72e8aeba2983ab63cc0e6c9feacbcd7da79dfb2f7f02ef5adaefdcc30338ebc3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:a192b81dbfbdc4ce03d94faab9aa009ce65c2097fa897fb5da3431980d2b114a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:1f05c714a6c01ad8c49930e0e9c22f5a242f5e244d700714dcf4824f616d53a5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:5214975226e6a994516ecf66296762864a9cd4db59be368f70b6146c88516b21
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:5c8595268fcd39375629676dffb18a343df5d908edb98b2ce8b9c1a94779c580
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:5810a5eb624c13ff786ff3958b1b62e040e7b911518eef485b44b5af40d3d931
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:d701d01a5fd22c7d17ef1a4923278bd2657db51bb924338b93f7a3d7d28ba11f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:d6e4b00b3c027c7e59d8853bc4ffdc805ef809f40550e6d0bd720df1e190ae9a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:3012c2c1a007c4868f115aff5c2495aff442296fa82ebecf326f429906c54f35
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:4c7ba2fed93466102c2c7f5b5a48b195744becc298be59ba405579e2bd4db747