Sign inSign up
Node.js

dhi.io/node

Node.js 26.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

26-debian-sfw-dev, 26-debian13-sfw-dev, 26-sfw-dev, 26.10-debian-sfw-dev, 26.10-debian13-sfw-dev, 26.10-sfw-dev, 26.10.0-0-debian-sfw-dev, 26.10.0-0-debian13-sfw-dev, 26.10.0-0-sfw-dev, 26.10.0-debian-sfw-dev, 26.10.0-debian13-sfw-dev, 26.10.0-sfw-dev

Index digest:

sha256:6115cbfcfcf9c2d18354b65f8c74022201435fdbd52f80d156054ffa76b6dc43

Manifest digest:

sha256:f8ad4d3557445c691d81005c47b4c3ae8e10e9239075e5180bce257be277abb3

Size

118.37 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:d41a32142dfffd2f98f7fb804b2a38af1ad75c9a26daf05143c286d895aacb14
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:dacef1be5cdcb0d4b0def9f1473826b397d06ec948ba89242891237303fa645f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:00ceb10eaaa38c9520719ec1889780713661fd82d78b1a839f69ffdec8f79258
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:4c43cc268412241f80d183f9817d16a9d909b67519039aa22be365cc9d2588ef
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:65e324d2aa83ef718ac14f82de16ff78c85995265e079471ff51f7694306ccac
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:5b3bcf348268d87c2bc75eea29b329ba721a3f2935d1ea6e66e59b7c6d8c7365
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:307801d49bd8e9478ebd017eaad69a55c3e5b9232d3ca7e003e8024936152b79
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:e1ba5f3210911b586258ead168c72a1e226e771fbf5b6dcbce4c47728a70e47e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:7ea477d7ec812c0ecc19cc0676affaef1b338192b9e8d3731c5965f51749ea5c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:071742bcbdb8a270a50810673339c5c8bf10ae8e26156314c831cdebede82832
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:2e4162771ceacc8604fd8626f95a06b23732c2e8e46cdd865b7d2f172e534059
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:e5b2a9970b40a211c1ab78c87b0c947c7fa845f5d8a69a202747f881c56518da
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:3b27052e32f67188b1bcf2f81c59055156167a58e2059473e74329dceac961f8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:7ec81fbf36c36955ed7d7a25645ad1e52648c50b598c37dac132cfa55931c152
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:5f83512706d984ee10c5e5f0988cdf13e2a1a6c304be3be4ba751a7e3b6e2389