Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

22-debian-fips-dev, 22-debian13-fips-dev, 22-fips-dev, 22.23-debian-fips-dev, 22.23-debian13-fips-dev, 22.23-fips-dev, 22.23.2-1-debian-fips-dev, 22.23.2-1-debian13-fips-dev, 22.23.2-1-fips-dev, 22.23.2-debian-fips-dev, 22.23.2-debian13-fips-dev, 22.23.2-fips-dev

Index digest:

sha256:5b9176f190bffdfe12f639248e14a1e760c749216cd4534ab3be9c6e5ca4336b

Manifest digest:

sha256:72c8e8c2b7ade71a484427a609fd6463fc33443355fbed19fd45b1a2885ed296

Size

80.47 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:36cf611b8db53c8798f937b505058b39e323b3451115428668561f625cbc4409
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:40df6381e6815f3c68d37d33c34662aa18d8a40fb6b3d5312cda75265f807f34
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:c0ab6c2f239b0d698e07d6383f1c789cdebb295245f51ca5c9a0bb577c4c7b04
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:c11e12280a57af9514e24fe93798724747b849ee36512624d6b34d1c759ebe37
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:468859c6d946f9e576f48810d31a81a593a19800ddc79ee9eca8a52ac42aebdb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:6c9915fd852f6e2019913d2c371e1d41c5ba313c93270177f4138da237e5dc05
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:0e16c58fa0ccd0d2817ba817dd751d52019bb04c848c4c1caa60cf5e4601d166
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:aec885418dfd83d99fb6e02985f588005a9bc9f029186a4e39bf96dbdafde52c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:4879c06d7df2bafdce662c5b31873d774d1faa396c495ad8effc82a9ac6a1bb8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:6b41d2646db507449e7b1828488f909c73f46aae844e107d99cfc9ddd7a5a47a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:eba079a529447b0bf6c19977ae548c8a8d73bc839ee1f6b0c1f255b3381c5982
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:1f7e33bd1f67d810e29baf98588199bf6cfcffa00543321a86c2c1593b055678
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:ce248cdeafa97fc7c9a8a34c1ec70a83ce122addbff1f3756338ed51fe045f25
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:7aaeb3f6d1b64381d3a7c959af3b46fd9ece565cbed7e0bb3a6ad09ae126fb10
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:5f64ad229fe1006af1e26abf789f82258da1203c3498e031911c76007eafbd39
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:ef37ee1dfdc8d47c9f0247f98888c3185684d7ec74debd10600b1baa50b9eb68
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:523e5c99b4665c4adc5f9d62b5f7851a75f26761240664f44ab4c8568801aae2