Sign inSign up
Node.js

dhi.io/node

Node.js 24.x (dev)

CIS
linux/amd64
debian 13
Tags:

24-debian-dev, 24-debian13-dev, 24-dev, 24.21-debian-dev, 24.21-debian13-dev, 24.21-dev, 24.21.0-1-debian-dev, 24.21.0-1-debian13-dev, 24.21.0-1-dev, 24.21.0-debian-dev, 24.21.0-debian13-dev, 24.21.0-dev

Index digest:

sha256:b91e3fa1c5f7e64aece04d5b8ea7cb60077682c00fa8620c979a916caa84a3b2

Manifest digest:

sha256:e8b4d97c68cee4e0fc3390b5132879ceae3262d3e7fca676a3766b3d4bf1c8dc

Size

79.91 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:0e08cb230444f9087014ad7e9ff29211ceb87aee1c0f81764344af15f747963d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:d8ec476f21fb5985433353d98ac34e69a721a8f1d8eae3d0f2858ad6edbf15c9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:6978ecde97def213120dca3f1f4c7e08e11c427e711b1faaaa9b8f5887b9896f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:ec99734f256e960e90ce9f0b3a97d7d3f8db633941acb06509f636f888a86aef
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:2f3a7b479362eacbfec54eb62d23e239026c02fe382116be0548102c922fc7ca
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:345a65abb84860958f0cd127789ad5a106389be841e11fa3b82b668b5ff93344
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:f9a11819d005138fc628ff1e11a0bcc84f2da3d5da1f671c4c2d905e709e43a1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:9b1a14eda602bd1fde2fdcbb48def18c95d33d9c2bb7633d25a94305403a1edf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:5fc5cef26406123c7aa17ff38efdf106d192aaa1d65701859e233bdab8b9a28b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:2e8f9b3a767d78a8034079ac770574558b6fab7c4d5e3fbd18d53c58d809f3be
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:23e672e17172c7b27f4e01f75f5085eafc68016fc0f68936353b60adb2e5b34b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:d5164cb71cb4b3a702d4406927b60725076303836b9a048f7a4231e1d020e7b7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:73b38396e4b962ee8c4a664c63047800994ba0623e72f78757e5c546f8dfad51
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:04b6dbafcb6971cf4440b17122b1061a5883c34c18fa8c6aafb3ff6222a7b395
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:73c51098cb9473a954600831b23d83db244c3c72d73b1de29a2967a982ced6fe