Sign inSign up
Node.js

dhi.io/node

Node.js 24.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

24-debian-fips-dev, 24-debian13-fips-dev, 24-fips-dev, 24.21-debian-fips-dev, 24.21-debian13-fips-dev, 24.21-fips-dev, 24.21.0-1-debian-fips-dev, 24.21.0-1-debian13-fips-dev, 24.21.0-1-fips-dev, 24.21.0-debian-fips-dev, 24.21.0-debian13-fips-dev, 24.21.0-fips-dev

Index digest:

sha256:b0b37a4ab3edc57dfda1b133ed501da628ba57f638537beeaa30ceaa988a5f88

Manifest digest:

sha256:4fc3f7ae987ba5fc1cec82637036ad814a82dae0e257d1f2b9c694469f272d6a

Size

80.67 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:cffc5b166a8a3231c1106839c3bf6973cad0288a64b6b1cde994a3588da44332
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:d85769edd991218cbe947fcda3a74876d7b32b72f5632a8bead16fe76fc2d019
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:de899c288b8bc8b23ca2c840817341300b47e5443c68754521a813ce1e4dd1a8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:86f84e50cdf571d55c4c0fb5112a88c003f709e2fa1748f8dbb54db8faa5009f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:90502d24d0d10ec806515a3d765eef5d0984d1e9c6eb8e6b63af89ac8026b4c3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:28be2834f283f33180527c7fd1e879cbb39221e3f857f630f5beb0519c1b5c07
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:d6c02757cfae36ccc0306a5261093c7f6bd30d4346f207dba309ee61cca0d91d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:030f445ea1519ef4a9851f64e04b699e5d3626c5768568a1d2714e5e8019cc1f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:97da92cda28d9fde5a22268ef586938e4f941d995ccabda33cfbb9544edf59b8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:8f773f5126fcc944ab7a177a856563f504e06c150b66dc4d1fdce4ad41731e4d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:5e32828fe8bc842077a75e7f01e8d0c84000739fe5d4007083bddf9b2a6f7ee2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:6587c7325b8a8d8947736e87142ea1963753130153dfd3b4778186a01c39c027
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:3b2040633f66754e8ec03d51a217db0cfcfb692b8f87245ceceb8b1dafeda10c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:e159451c58c7b620f34bfccfdf653e7c85cab867b56087524216c89bc687994e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:2daf15c1dcd6390d6d1e0c76c01e347b12cc826b973f0c0b50a5b8dfb4d2c33c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:847037c2a8580194176c2d6438d53469da940e6954cc4c06fe929614dc933cc8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:0ee7284d6bfd911b0984c014e6918531c21e3921cbe1b2f6ef17d3873827f7aa