Sign inSign up
Node.js

dhi.io/node

Node.js 24.x (dev)

CIS
linux/amd64
debian 13
Tags:

24-debian-dev, 24-debian13-dev, 24-dev, 24.21-debian-dev, 24.21-debian13-dev, 24.21-dev, 24.21.0-0-debian-dev, 24.21.0-0-debian13-dev, 24.21.0-0-dev, 24.21.0-debian-dev, 24.21.0-debian13-dev, 24.21.0-dev

Index digest:

sha256:ad73bb38988052d9c17677cceaa4eb134d6c9132a84c08770e1a0162d02d1a03

Manifest digest:

sha256:9fe9e98c6f1982f8d18f62fdfcf8bf9b23c739d655692f1bf6a8b03871dcc1a5

Size

79.91 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
3
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:49494829818116a6ea193dc383950508c9ee8425a38816036ce185d4b59561af
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:86db1d504d244647cff5edc03c5a4cc9b7bf49ece5839764bf71ae0908ad6473
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:24f357fff19c752be57bc56e0f8bc5f4a4a1e33a6c88a99b029fec119301fc29
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:23df565d26d238bcdb1e2bf77116d76a637b5e4bae03204cb3be755442c1cf54
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:2777cbef552c49ff0b3919bbc27613ca90ab5950fd49cef8ccebbbaaa7822a3d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:0e8430ef7130248ddb2257139d5d7c365cb506ddce252e093206a96c4d162427
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:7c6656816f80c7dcad812e123c3eb891713988085c55429c71c5d5ff5279b9d1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:aa153049fe784e4b2e1006f287e6a5862bccff9368e3c045a02a390f8d702b0a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:2c02ff42510c423b3aeec5a074734fee630aeab8d2a519eabe60f5e9c523ce43
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:36b3bbe16aa71c9424b38518532cc3bf257873d5bae4bb76791a607f426e99bd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:2909fd7fb5d65c88bdce17366e8b87e6ad16a22d1c8c60feb9cc2149242604be
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:46835bfd047a2f93e8cf0cb009fa6d27b8058f61302e14c6cec2949149f61a3f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:07ceec1057e74ba06c081ecf5926f7fa8909dff9b2d57cf3195190394e9ed39e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:3504f2216023b71254c1868738f36982de7ad0afcc6041a17a1e6d844688383c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:1508275731b6c35f438144eba53df7383c599cf7cea403fffab05650a00a23c7