Sign inSign up
Node.js

dhi.io/node

Node.js 26.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

26-debian-sfw-dev, 26-debian13-sfw-dev, 26-sfw-dev, 26.9-debian-sfw-dev, 26.9-debian13-sfw-dev, 26.9-sfw-dev, 26.9.0-1-debian-sfw-dev, 26.9.0-1-debian13-sfw-dev, 26.9.0-1-sfw-dev, 26.9.0-debian-sfw-dev, 26.9.0-debian13-sfw-dev, 26.9.0-sfw-dev

Index digest:

sha256:5fc3a277a82a6c6e0964e1f5d1a65cf2ca14199f1fa0dba4f59f5615328b80c4

Manifest digest:

sha256:aea9bce94226e126facbea51443681b7b9e1d349cab9ca19da27e7f14fed03cc

Size

118.26 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:da687ebb0997d3ea93b91b8ffb361b108710cda5dda87edf19bcdccd619d894e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:32477e7736edf381a5b3fe599d36ce1a42a00b7d090c3f17f9e9e5ac50aae7bf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:5502463f8be8a731d2611bcbc61afb1162b0bf7e3f463346f9edb1ab23c0a7f5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:ac1b8a788730792966275d9f49ecc9769cae368151179ff0c816400daff3f758
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:df98bd61eb1350a7b2a214999e7fe6a106cd94ab627d498d3982cf5e7f84df78
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:d0d6eed6e21767e74ffdec2b80fa393742fce281c6dfac0a9b01308a214f7185
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:4ea397cb34a69f503be42228c5f38fd798cf8379770209267e2db2718c31d001
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:b4fb1844665d7c2748bb26f5473fd6a8f5c945337161da8d2ab2cfdd9336bf04
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:e7dcb4ff8a04f1ab3ad4b3c0b7cd9021d3f7f4acd9fb05f7bcdd541e3d3a2902
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:d24c4262b186613207206d9bb5606793d98e969437b0e6dcd2dc2ad7be204a52
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:cdc65f423aaca88e37f62465a9a6ead7f822723e6f95e6fa5eaa3852af3fc841
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:866e0e72bba8eb0f1fb75d54ccfc70ec35f4c09bad9e1a42cbc19d78d1fffeae
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:d78fbd3f2e5fdf1ebd2a161dfa60da4a99b34a51a1d3afd95b3748f2d31bcafe
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:27582c4cd14a1e8fda6684fe16bf95444b6b0076397aa78aba7dfcd8745e7f2c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:e209063d4518fa33dcfd23a157f8c0c9021fff6f50203b8d02818424c505177f