Sign inSign up
Node.js

dhi.io/node

Node.js 24.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

24-debian-sfw-dev, 24-debian13-sfw-dev, 24-sfw-dev, 24.21-debian-sfw-dev, 24.21-debian13-sfw-dev, 24.21-sfw-dev, 24.21.0-1-debian-sfw-dev, 24.21.0-1-debian13-sfw-dev, 24.21.0-1-sfw-dev, 24.21.0-debian-sfw-dev, 24.21.0-debian13-sfw-dev, 24.21.0-sfw-dev

Index digest:

sha256:b098d411eb0c11287f195c2affe1247bac392650e51a9a3a6643ac4dfa56a6cb

Manifest digest:

sha256:5a38d098d2112f3c92372371967696e06b7bbaadd4bc326294270b6cacb91bc6

Size

115.77 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:199c523ab40fbd35f17986aa8d6a32fcc2c19da519ade8d62c4515017a87c8c7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:ee71d5cc7581e831d74346cb6db23c3a5073f7f50e0a5193bdedae68e579c52e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:d3fffba36be519a774fc79d251c4d3b81084b9f9f59939d6fbd141e333db6285
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:70fc92d08ea6de8ded46c029042dbe92036794c567f492d490f84796cfed3d9a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:8696061a07935a6c5bd24b201d0c0f530cf9f4f92d2bc0a444c8408480c1f9ed
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:8033ff6eee981d6ea0db1ddf772c388ff4d68e7b2bf45170a1055e7733077d33
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:c7cdcc82ce08e2ef0cc0af8a33dc2b5475fa15216fdd15ff9168416dccf7e15b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:00664dabfaaff5fe61d25978c3ee57ee6649a2692a5478d58e94def1c1688ffe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:e6b6840e6dcb5b8f36e6a7b79bef246e7b2adb2b1c0cf7d35864963feea6270d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:71483ca95bc2e08d103fbed14cef2002340378ef1728a891c1c6ded8351c4c2b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:68e0cbe46b9d3fc8e3fabd26e4b2fcacde791bd6443bc660b1103794064a27bd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:b7949320a3395443659ea58897a253c97c74b68e004772edb59a729b271b46a6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:5ba7b3b60423b1adbc41022f52260a6e64b60cb3d9b64553790703b9b21af3be
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:26dad562afe4d4d8ac9fedfbef062cd02da4940bda35bab56d6ab34eb0bc0b0c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:969ade02a3613850d8bd12ba6ec7979794070159786c40d5da9210055c1c4837