Sign inSign up
Node.js

dhi.io/node

Node.js 24.x (dev)

CIS
linux/amd64
debian 13
Tags:

24-debian-dev, 24-debian13-dev, 24-dev, 24.21-debian-dev, 24.21-debian13-dev, 24.21-dev, 24.21.0-1-debian-dev, 24.21.0-1-debian13-dev, 24.21.0-1-dev, 24.21.0-debian-dev, 24.21.0-debian13-dev, 24.21.0-dev

Index digest:

sha256:f9518ef202555322241e228bd85cec3a72f14d35aa1eb47853f0fd3ada928e3a

Manifest digest:

sha256:bb3884eec35102a11cec2fc6250cd12e8bde584ba0a631e6102e71a0383ca178

Size

79.90 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:c59b3cf8ed0c3e28ee7f7cec6bef29e87bc48950715f8437093f2e398cecb7c3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:9922aa1b8e72bfff43b0eeddd09976252f3be655753b35676bfdab77cc372172
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:6a78fafed929d6e4bfa548ffd2232ee897c59ce184e9e38d893779cf54c3abcc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:8edea29d548eacff78dc89534f1b291ee7a676c5af33d2d684389b9d34d0151f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:5ef7d20dd0bb2b787eac2246f3dd0585264b2d01e3b86b60478e2cefbd387bcb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:ad69e77a86d44a7d4f7c54ff235ebe86a588bd37b5e9d2eb9ddf31fa464d955d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:edefbe9c4305c521125f07bd93ac103306759bec23755b93f20e480202f6dbdb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:c0025af22cb5f3eadc1605546a1ecfe060eed6ed83ca479d706e3b7c2da59c99
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:10792876bdf7ee59099f0ee8425a76fdaecb0b335b4bb499fd11acbae921c474
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:d2705d21d1283c6c6e13417a7f2dde919e57d7cd8a8c0cc7330e3cf66df18f01
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:81655bbfaf2067ea3b9e37b73a5cf5428550dc76d4d719c484d783d0e5d6f79a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:46d0a5e1d6b693121ca5b3bcd498ebc3149f8fca0d62cdca327107e01049a10a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:fa8ef3cd54305fefaca3f7f8d7f63662f267799625b05ff97efc9e122a2f7ad0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:443cddd0d45bdbfcb47b73028cfbb873bafff3432c67d3d2273691bb527413d2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:4274e393bc1ffcab5fb86450e45c0723a8ba79cc56992ffae62e7023e41d07b7