Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
debian 13
Tags:

22-debian-sfw-ent-dev, 22-debian13-sfw-ent-dev, 22-sfw-ent-dev, 22.23-debian-sfw-ent-dev, 22.23-debian13-sfw-ent-dev, 22.23-sfw-ent-dev, 22.23.2-1-debian-sfw-ent-dev, 22.23.2-1-debian13-sfw-ent-dev, 22.23.2-1-sfw-ent-dev, 22.23.2-debian-sfw-ent-dev, 22.23.2-debian13-sfw-ent-dev, 22.23.2-sfw-ent-dev

Index digest:

sha256:cc82851cedde0f7d4469b4adc8c1b12749ec000338fdd0e795dde877ba14ab71

Manifest digest:

sha256:781d8bbd2cf9a9da5bbe08019e275d7944287baadd34e1e5a7621805dfcc39f7

Size

116.29 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
3
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:e358dc1aab706ecbf428ed172346840f0e9ec9173535aeba2b3c3002cdb9e03b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:c837cdd9111b6983de45e02d22c876bce62696aecb7af7c12c9d3c6975650420
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:a118502e65f2972f69a2c1536dc6ee02f14d90182c1c429cfa648fe4f14aeb81
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:6e47f62ddd693f445f01fe1713e91d79dc5cf0ae4a920b2d760532821c8952fa
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:f61c78373a9a74d421c2e7711f842b4a1de459684e95fbbcfbbf8672a160566e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:89ede050199be5f4d39f7b03add98109795d9ee8850aa7c25084fecbacc1716e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:c0b8fc717fbcc883dfe6b9b1b9e518396479a9d2d26d4527715832764dbe2068
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:41a3decfd1ed1a513117eebf234966ef16283fafd6b0a96fe027d29ed68a817c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:4b35b9af4e452a76d365bb6a791b2e21a0897acd37979519e00ac353cdb36a31
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:426264869f7776964c220d623aca17cf1be3b37d9841365f215745689669eb7b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:0c1fe9be0ce99404ba2050d6b4337b39204b139e14954f9c1edae2cbeb528e41
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:d99ce2e7c77fe5199662c9bfbdf06dbe62ee960f447815e19f6b75b7d9c4f068
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:edfdd4813d88ca7412fba6723887ab12dcc08efc1539681b78064709ded1f8ed
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:9c6135354eeae0b0f2d582b45e958017732b917dcc052f91f8b23af0e7dc8d64
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:18af11d698626d4c80b521647097dcd13af2468b060abdd18112ff5418d2480e