Sign inSign up
Node.js

dhi.io/node

Node.js 24.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
debian 13
Tags:

24-debian-sfw-ent-dev, 24-debian13-sfw-ent-dev, 24-sfw-ent-dev, 24.21-debian-sfw-ent-dev, 24.21-debian13-sfw-ent-dev, 24.21-sfw-ent-dev, 24.21.0-1-debian-sfw-ent-dev, 24.21.0-1-debian13-sfw-ent-dev, 24.21.0-1-sfw-ent-dev, 24.21.0-debian-sfw-ent-dev, 24.21.0-debian13-sfw-ent-dev, 24.21.0-sfw-ent-dev

Index digest:

sha256:b5816212eeaa191edb1c7d324d5da5ecb6b6fa26bf4d8efb1180668edcaea91e

Manifest digest:

sha256:804087e83e26082ff4364fb2fa491211d7f602f9117ef147124971700f3f4fc8

Size

116.49 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:a04e5a16b10f6005416780c6ac3df77e861cd242090c6b5656863026f860bc6e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:b069d89cbec0a2a12b63d938a06ba43ae011ab9d0e2a6f0033bae21876dcab24
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:76cf85395267f6516e93e195ff695a4f4a4c27eee8bfffde8ea4749aa7491071
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:15e8c1665e1a772e4b6d5604bbf0bc0030aefdbe590f7705f782e1cd93651158
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:b89e77258c406f2814a8edc46fa70291941b098d11b3c7c668f73eccd5bbe249
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:0ee5418004ce80a5778889f59f96fd703b2a9c2d5c3b94c9e58c7676890606d2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:e08e2dab939d4f07e83ccf41065f56e6cf9bebebae19e397d3ecfa4f4cb16bcc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:6107786a0175ce24fbea9c76c762ce1405ab61c54de4c10d90435dece46da9df
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:0019323e2e8cdd5c5d3fdd6219bc722319f0a7d68b9f7beb6da14971908385d1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:55e36fb552e66f6df5dc67ab397429772518dd671ff0fbd1e01bca4eaf9c4295
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:8891736a0d595882fa8078794ef8fe6ad76d10989f422c27e2bfc0921cd411f7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:ceb6dedcb713380547c1276c1f74be9ae24565f9bea603e44d3bc3882f5d2408
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:6e735be6113c2e0495ad443ff3d0be52737edd8b47e262716c8d234d1ce9db2b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:1dd4acddac7a76411e8f5539caaa017b4f20378a4951b3bde935cc717ffd73ff
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:a90b73875bed25668811898ad7ee6fc57250b63817a4f384e4c1d86156df0fcd