Sign inSign up
Node.js

dhi.io/node

Node.js 24.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
debian 13
Tags:

24-debian-sfw-ent-dev, 24-debian13-sfw-ent-dev, 24-sfw-ent-dev, 24.21-debian-sfw-ent-dev, 24.21-debian13-sfw-ent-dev, 24.21-sfw-ent-dev, 24.21.0-0-debian-sfw-ent-dev, 24.21.0-0-debian13-sfw-ent-dev, 24.21.0-0-sfw-ent-dev, 24.21.0-debian-sfw-ent-dev, 24.21.0-debian13-sfw-ent-dev, 24.21.0-sfw-ent-dev

Index digest:

sha256:e3a1f042a6195ebfc326b72a57db67d6095e0ccebed6df8deae58056a34ca8b2

Manifest digest:

sha256:83a7e8cb38df1197c381bad5dfed73e0bfc4ebbee925c424e998e1f808f5de33

Size

116.49 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
3
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:b71d27ee4fc8d4c16e2ab37c02aa644c03c74dbef90ca3e62e09f41e198acc15
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:c2f94081dc6fd294698b88497c5e6678a524261e8a92babd87f7b4f5e51da891
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:0a57386f166227fb8676539b3e8f1d695dfdccf5465de908aea960aa5f674845
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:f39e3fd0c25567d72a84f23b880f53888520783a64abdfd2512014ad701a3143
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:950c4249b2551c17b1a9cb03e1dcb67cf648f4b0d6b3693b83fef5d266b1051f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:9ee030b066b851dc978c127f25e9137647c0878b551eb96c661fd2c747db7b13
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:5cfc05583ed35df3bc8b6a267408fa48ae16870581675afd3fe30f095350f514
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:df8f405945d4b20c36a83d3281d9b582df56838d970f2103e62875845b485333
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:4aedde6ff3a67b4a4ad940014a4c03a8ca26d562affce2bd2d176e887a103233
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:209b9ec0033d598ec637b34204f30d3981d8d3cbab9d2c2282aa5a1912204004
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:4b398cd73adc56ae913476fe7018ce66ff4151b9302402e251a192d05ca086ac
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:d52f5f9029feed78cee4173a083df395adb38d6a48601aacf5ed18993e487a4c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:671b43ea9b248af791061d9bee058c9d718ecd7a6acf2e63f7bf5fb274ae2692
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:d694d7735f9dafe532ee387e5741fdab47c0ffe46506efbca693de2d6960adfa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:55915d9ee0e6e8cedc24ec2a00931fdf0c94a327d63c07d55d7c85c025468c8c