Sign inSign up
Node.js

dhi.io/node

Node.js 24.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
debian 13
Tags:

24-debian-sfw-ent-dev, 24-debian13-sfw-ent-dev, 24-sfw-ent-dev, 24.21-debian-sfw-ent-dev, 24.21-debian13-sfw-ent-dev, 24.21-sfw-ent-dev, 24.21.0-1-debian-sfw-ent-dev, 24.21.0-1-debian13-sfw-ent-dev, 24.21.0-1-sfw-ent-dev, 24.21.0-debian-sfw-ent-dev, 24.21.0-debian13-sfw-ent-dev, 24.21.0-sfw-ent-dev

Index digest:

sha256:a8bd1a384c790c9ba5993f1d845054407182f5c769acc5c20f8969511b622e5e

Manifest digest:

sha256:7a26160e12c4e065a207e8c12e2db733ee05c0835996335ad7d9a97924b36450

Size

116.50 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:aa6b605648096218b892e8c5cfc05a1ab576453d0ff06a0ed116642591059a55
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:8b552eb877603a6b627664d7ebcc33fe94fba444faceb7d072131fc2d171076a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:032eeb39532c6a1d4df701b28c8a422205e598f7964f0be80daaf53798de20e4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:367650ccd56f69553cb8a2a63b6c57ec3b1fd27ffa6d1e3724eb9c43761cc142
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:517ffbd282498031f323681bc3c44e1e9e71eedb70ccde188eccab8d86a15e7a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:f3b53b860f19b09998ed3a622a08e7b99e9062eb121706fca551005d41a80a25
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:5191aeab2f8f1392a06be10e352424d466fd0b1829c39cffab026def58381f62
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:71f7eae84bf5dace1a1d133af49fcec6b27525abd8211711ac3dd5cc87cb390b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:f855646f617ecfbe8876274961c2d455f262d7287c47803f826e6d29a148f694
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:d7ab4fa0bc0d839e02d4c820f37edab933b9692af6650f5149a70c0c6f6765ad
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:86031765ee47d0cad8d35af493e2a3dfdf87b14a3176fe5db1e2fe6ee7228239
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:d64c08d2fe304ecef784b8f02dab2fc8d1fcf7baa272975f43941688baa1cb10
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:53800b5ebbfa2e0e98cb9dc932100f1e610239f5387dc3e0bea80d5c5051ddfd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:33a010cc57055ab575d84c07b45f7e7bfd4d4f489af1794a93f6963823f33bda
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:720b44bf831a83a72b7bec253c836bbd8b89b8bc898040fe0654d9a12225cc47