Sign inSign up
Node.js

dhi.io/node

Node.js 24.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

24-debian-fips-dev, 24-debian13-fips-dev, 24-fips-dev, 24.21-debian-fips-dev, 24.21-debian13-fips-dev, 24.21-fips-dev, 24.21.0-1-debian-fips-dev, 24.21.0-1-debian13-fips-dev, 24.21.0-1-fips-dev, 24.21.0-debian-fips-dev, 24.21.0-debian13-fips-dev, 24.21.0-fips-dev

Index digest:

sha256:3255203f97243d14bfba3e868fe518447175370ca01d9f984c84a8d0ca475228

Manifest digest:

sha256:70a0427fb7589ccd6f07f646f1435d31055203427b3f7314abfb189652eda29a

Size

80.69 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:3763b34f43a8545a20e009e91a466de97a5f125fa1cc7524e34b66abdf8d2515
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:0cab3d5d674883da66d61bffb6df5498a2218eda8837c80603a7b05c574e65c0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:e8321582dfe04b6ac9b3137748e820961b13672cf83963001d746197cd89b8e3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:530ab29c80a33a5224d957e44aa33ceb8f63550f6c73606d2ed3e619c28e6cec
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:26945a603ca7f198b937a069c12dce54e2ded08b0bcda590f2139df9343c3e9b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:062ecbb30a696faa83b80462981746c197cdef683cfd7c1b320e15596c07f639
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:cb51d0280dde19d347a779aa7b73b89adfea5f90e45b2fb353be074d9d1bb40a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:3d26f0da0c5ec180c1a448300b2836e1175c3fb11180842e651919a3212e8c8b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:c31a388dc4a0e27ca508ecf9e4ee7860bef01cdae8c685c3f0aec5245df53b34
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:2d0c1f9bf5641419038ce8030cb1a1c7d0bbb9db84b1dec3c87833150d34a68d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:b43cbf3ac0f47ced6c81d8d0807f3d029298982c00656550b2cfd467cb838f61
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:ed6861c59b5f8bf04a4a3b049d504820e2eac4c080d714079805fb2722b34286
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:83b58838d1817ab480df48a14814dd75aaf398fce44bbd7ccc2372850bb1ffab
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:524c96e9879366aeb70d8833dee47022bfb9b200aaaaa4d46b04ed1df148c8d5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:712c788d7e6ca8c22c8716ee1e90d6bf1a207f8f9d925453440f1cdda694f57e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:2c57191a262b4e655a25be6af789e1d08e4c969a7f75131902afb2646d99114b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:bcc350c542a6899c5b37d2742279a5fe612acd0a119cde29fcced8de9becfe9e