Sign inSign up
Node.js

dhi.io/node

Node.js 24.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

24-debian-fips-dev, 24-debian13-fips-dev, 24-fips-dev, 24.21-debian-fips-dev, 24.21-debian13-fips-dev, 24.21-fips-dev, 24.21.0-0-debian-fips-dev, 24.21.0-0-debian13-fips-dev, 24.21.0-0-fips-dev, 24.21.0-debian-fips-dev, 24.21.0-debian13-fips-dev, 24.21.0-fips-dev

Index digest:

sha256:31138ac7be3bbf75bc699d921d9185ee841f730adb1ffd562bce7e832da1ed79

Manifest digest:

sha256:2c32609c4dd2f010ebfb89d7bcf81622e5c2eb0e9288cb3658d28702a055c902

Size

80.69 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
2
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:284945008b4a4065ea48d104e82abe044ed8cc2d3e5467ed610b27877903cc21
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:8f8c275759ef5f59ae6021d8b5f59aa6944a1f2f652219f2492482d91fec2eb0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:26439ba8365610241cb52a4d0201da8f43b64df1a2093afc6a2e2939f6a39d48
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:f89e84effa88134f0f4080f402164fff08042f792ef56322d5aeb7f3adbef0e5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:eb12dba0598cf63d71ea738f1b893c8e8ffe7378e36e155cec352a05cd850dd5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:5832ead56b3f4a1a1ae773d13674500577d5da241bbc2c05b7789d4d76d8947e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:9c96b23a5a656ce1b357a2044aa4082e49b8c37c4050da4e1ea6d07bc3e8d889
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:42a8af3d09225e543086d4c80459737950cecdb9740c02862a750ce8b18bbfd9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:3d3e9448c9773a54eb77eff7fde24312a76b9005327ecb778130bba2395b29bf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:cbd71d500fdfb0fe43f8450e334746db7c73f7549063f9f1053353e7ddc55b5b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:a1cab5e94a5aabf074b8c09ac9d931f5ef5874f6ef5c9683e31069a22e3edad3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:a99f81935210bd2d6d97df736591d0ec874bb131c3a5b81cc7a45f83ffbbb34e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:d03b6d79095e4619ef91283ae37619a17ed32fa4963e35b4d003064788bb4217
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:767f7029a30079e0b7a87b51120901e1bcdd2b646312967fbf00c3284bc6ea79
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:efc8724654566ba8ec529a73a28cf0ef44cf8288c68eafc263516da5f32328c9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:f30c015d62849cab33a4e6cffb556b45b75967431fa57007b8b6cfab0895d9cc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:e25caa48e44a72a187acae414482e8e306fd012c461f6a0e1407c4315e431606