Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

22-debian-fips-dev, 22-debian13-fips-dev, 22-fips-dev, 22.23-debian-fips-dev, 22.23-debian13-fips-dev, 22.23-fips-dev, 22.23.2-1-debian-fips-dev, 22.23.2-1-debian13-fips-dev, 22.23.2-1-fips-dev, 22.23.2-debian-fips-dev, 22.23.2-debian13-fips-dev, 22.23.2-fips-dev

Index digest:

sha256:629c80d9abdd0dede275f3689fac68de70c9c61fb3ce6efcf8b36b961a1b7f2a

Manifest digest:

sha256:dbb28eec940a480a151e861d56d613dd19a270e661df0af800960371a231babb

Size

80.49 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:6c3c45f34d3492b8f13db702c19bf8eb03f29b204c1e92b9ccc955f13108a138
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:d703cf11dd52086e40c4b62a6bfa3b620beb27317dbf18751e2c13378da24d23
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:47bafb952d6191993f6f8e54d434bd04eb07a4ee5c1ec77e3abbdf66046123d1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:8dec967e0745315f4406ea5811dde2d577660b47c85c83dae5912fe7c13b559d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:691facbcbc0577e3b10ce7ddf9cbbe18ffd44eb056d437c805611474f64d4007
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:07e080a29eb82e16deb3aa23aaab9d391319d0e7a0a261343081a689423d4324
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:e08911c5fce188fb8d0991fb9a64da4112e6e55c8842429e1e232062aa867743
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:3e2b5bea9db6fb3a8107503c59ee10eb4561429613bcc1d634635d80d1f6fbe8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:b3eab0083895ab04352f1f95be780a53016674d1425d4f255871cdc4d97a64fa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:d7747da648e72168dff4eddf49d4240433bf1843f7db074e8631e88bc900bc54
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:15c30827f340138f06bff7c3a70cbdc50cda418ea1cd43cc272a4cf00acf7ca1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:ad4505c5c8df6e2d58348ccce9ff27fda50eb49c1bfa3f02e7f6249b89dc02ed
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:a085ac6d4f12d410de2a85e22b0e7a26e10812ef002107d5e12dc971bec89668
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:e670ef6f6d7c093e3853af8746691b9271be502a67dedd4d53c38ad7604f40d4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:a949400d90f1dd2d732397f618f35a719099eb59a4bcd949d325d34a94c50fce
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:00917557947eb9fa300a682235b40731c8b6d99102de6a24525cad69cbe13bc0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:46fe7cccee5ea8762e478b08e26caa5d56461a449ef06b6df26ed81ab65c700b