Sign inSign up
Node.js

dhi.io/node

Node.js 26.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

26-debian-sfw-dev, 26-debian13-sfw-dev, 26-sfw-dev, 26.9-debian-sfw-dev, 26.9-debian13-sfw-dev, 26.9-sfw-dev, 26.9.0-0-debian-sfw-dev, 26.9.0-0-debian13-sfw-dev, 26.9.0-0-sfw-dev, 26.9.0-debian-sfw-dev, 26.9.0-debian13-sfw-dev, 26.9.0-sfw-dev

Index digest:

sha256:37e5f677af5837a600d402399418bc04bff0f4362f2fcfc00a4d99b52a11db2c

Manifest digest:

sha256:625ede559a7194bf019a2fbab755aec00a6298597fe31600a06eae08821555c8

Size

118.31 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:37bed4e4ce19e1022ac14360d818f1d11a8e3d2626ca4dba46c12e0d24a8865a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:a7e32192c1b0f70ee8600bd2328030ce647169da1d9ff4f5a37877c8d310646f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:e1d5b78fa1724b63cb27c2ad60bca6c3d51444cc118f2a21934d6fcb9b7ef143
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:51ecf46051a53518ecc933891710c5c491399d066bd3c504d0a1b73f179e35d1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:d0ae805af66c83512b0d577a67299dd479162d031319edb0293d42ddb46687b9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:d6173b90e06f63649bb3880c1d76c54e20950d18cfcf2fd079e3a5ff39073fe2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:a70daf67a89036ca89cf3315ff464e2e317c20a269067547fbb952dea8bb8707
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:dd3599b6fb13d98e2bdb82248c6d54929111e9a5512fbad7c445087f82f41617
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:597172cc922e75b3b73820d23aed123ba1d16be216869cd5727dbc0be248d804
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:7c016d55faffc587264e8c38e12c9a1bece3f464d42f01c27d383a99be10da74
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:88d3362e8ae8f965b8f4d5d795ffad2cecc00a9c7679691a556105b15313c40f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:5c760d683b66142154abd1c30bc06450e8a857d93f0e4d0c8400272800d2d0f7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:5bd7a000c068610984037dcfbf654395e084181cca2db26baf2291c6fc13124a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:9f7af7d31efa9b7aedbcd1835566ea2a29c409f75801461e40161e281c8cf95a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:c52e17ac1e204b1f23df47a6c6677b2d990a18a3fc4ec5b2105af66ac61f185b