Sign inSign up
Node.js

dhi.io/node

Node.js 24.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
debian 13
Tags:

24-debian-sfw-ent-dev, 24-debian13-sfw-ent-dev, 24-sfw-ent-dev, 24.21-debian-sfw-ent-dev, 24.21-debian13-sfw-ent-dev, 24.21-sfw-ent-dev, 24.21.0-0-debian-sfw-ent-dev, 24.21.0-0-debian13-sfw-ent-dev, 24.21.0-0-sfw-ent-dev, 24.21.0-debian-sfw-ent-dev, 24.21.0-debian13-sfw-ent-dev, 24.21.0-sfw-ent-dev

Index digest:

sha256:d9a1bf377c9a23224dd1aa8627e38c06ce339cf2f7d2e374799f3d5dc8435a4e

Manifest digest:

sha256:90193c0aa893eecd96ef11b77261b79f2145a626467b72451f580aaa0877cc16

Size

116.49 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
3
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:17b75e1b39b61e0cf04a5bb5de032bb87ad3c0e0d5ffb8bebab1fdc9a8217a3a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:3eaaf51d3cae11c3194d3d490c4135512668ac0bc72af4d2d5b7eb49fa7c8a39
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:2a897a291102dee88d794f2c6ec67d80a0e482fa9c2508a6705240d482d0af5f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:048c1c877544d8908d324e62e8ad2e47f70e0c601a055d1fede244e75852d6c4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:ece48210505f06bae7b30b2e3b85e7e959e6fdf4b29cb53c15c7fc313c2e6e67
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:942a98ffb8e6ec444ad7353064cf946c17ee3eaa678bdb700061a6da9ba9d960
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:0476696c37c75a6ef61c64f3373bf5f2bb08ff7a5bead19cb9d576c4278768be
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:4571ac2e6f50aa34e396812bebdd29eeed4dffd9453b5d24a3e845a7da5fa996
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:9b433457edf5022d5b6e5a7bc5c1e3b114b3d9cd7c9f429a2644e28111390a83
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:03a6cd3d3dc27c75953a5698e7f3a2d756428fe11ad19c5a37d5854cf1c467bb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:621c53b5708ad9d7a3f863c0911eb86af62e0b8fceec14671a6da0d62d2846a5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:38ea5b31fb9c4d7173b02c343996166309ab070753047c2191a8f36652c64637
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:41c2a02ffcc4ceb942c1aee105bafd152623e8953d29c06e3480161a7603f653
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:ffefe8056927ed0d7eff7df2087b5ef3ba8a6af5d054056c0d5f1854590851a3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:0e7fc32c256f5badb96e84e2fbc01421a69b478b6811b1af60d40141f64d6b41