Sign inSign up
Node.js

dhi.io/node

Node.js 24.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
debian 13
Tags:

24-debian-sfw-ent-dev, 24-debian13-sfw-ent-dev, 24-sfw-ent-dev, 24.21-debian-sfw-ent-dev, 24.21-debian13-sfw-ent-dev, 24.21-sfw-ent-dev, 24.21.0-1-debian-sfw-ent-dev, 24.21.0-1-debian13-sfw-ent-dev, 24.21.0-1-sfw-ent-dev, 24.21.0-debian-sfw-ent-dev, 24.21.0-debian13-sfw-ent-dev, 24.21.0-sfw-ent-dev

Index digest:

sha256:eb2ee9a8cb15517f57447d258d5affd6d0607d40f4e20f872be289b42ba93a1d

Manifest digest:

sha256:afcfcb200616a246dbae3452b376f57f05d789bee54cd8aa5af6ca60890bf2ea

Size

116.49 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:222cc5527395b4ab66ccddca857300fb250253b56db399070220bf4121a0a511
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:e1839072be03e7d7079be251b1798e7fff9e76ee245d76b5e2ee89df9fa5acca
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:91161fc3adedc9ba311232074a7aca64f0edbbff6eaf3b4f6c43647a5d0a51f9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:74c36342b8fc955ff1892b5c0e4b5fb801d8ab1cb8329548ab3cead4bb45cc0e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:cff62331ebccb870e043b49deeb6e7e0bdf9cbd748b40ef1e3cd566f8026181f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:c62a1042f966140c7b004558e5f76d279c45dcaa378cc7b505d4712a6dd9ac5f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:0c4a9a8750a8f9bc84796575904b6870b08014eb15073899821ad5fbbd14b073
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:c50566204728a12d2f3f04a4ee3df8aa64bcf1f9593e63517bd84b66afd6adc7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:14caecc1f7cd5bf8110a03d5bbb92c9fac55f2bf456a4b97193d4ac225ab6f4d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:957a1bc0cfb841b5c0fe10e0df40281fd24565511fc550d84a40c3d4edf24051
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:3c4bb0dc21fc38916ecb2cb94bad368f9b95cedfe32be16cf9b36b8453ae01b7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:d2924bb0cab9f3c83eddf57db8a072f5f465fc7ec52730c58b111a4ccf0418cb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:5bad49183250cff644809cb2d788bd999c480c4f3cdbd928f9c05434dc62d698
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:6a34b5435e1dc7d6798fdbd0e38b51464d2c85e389180c20d3078e2ca68feaac
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:8fad4b4153a74129673681c20ce4b0dbfef03e823c00d6358b5e9ee0f96ddaca