Sign inSign up
Node.js

dhi.io/node

Node.js 26.x

CIS
linux/amd64
debian 13
Tags:

26, 26-debian, 26-debian13, 26.9, 26.9-debian, 26.9-debian13, 26.9.0, 26.9.0-0, 26.9.0-0-debian, 26.9.0-0-debian13, 26.9.0-debian, 26.9.0-debian13

Index digest:

sha256:412499c4234e03080e997d32194100d5cab3f86ce9e6a04fadad2615427d2fcb

Manifest digest:

sha256:87da8a0b0b33a99d22ecfe6014fa0207e788e2ada0f54eed817678d1e4ddcd3a

Size

42.33 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:d2423998c7612e42573af7ef8bf9ad5187afb7e8c4a28e9cb09872d865d0a931
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:8f0e6b93288263028191c4948ce1d98f86292229f5d2de75eedcc6236e445eae
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:4f9052c8a40d63f33ffb25980cf19c0da69d02158696e3c15b67d054bbd679cf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:456c0643d181d9e3da6f7a2cb27b0e41b7d2ac006a93ddc875f691c6fc219d60
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:cb6226c8a55fcf79e810d09439d35442665fb7b16fd17e9ccc31aac1553f607c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:3a070db58ea7b87ba24a671095d061289db31603c776d4b204d25bb63ec5594f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:ccf51e8e292f030bf6b87e76c6b535e8b6fa57eee81962d1d40d7d0764e106f4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:f7a964a4e891831a8aeddad24583a9f972b8edcef935641444f26d9f675382a5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:8ea00715867da9eec2f6e89b683e516edc97402e8c0cb1590f0bb91e71a9b86d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:97582d72ca46dfa7eebd8c1bc729e705f1da471bcb5c0709c8f1e755897c8237
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:0ac68f3792522cf256a8df0c0c1ed02f9a18b672e3ee650089b6067e6c7da27d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:08c8c681a93911d8710aec9d8fb37fd7a8fcc73eb7c7bb0ba099d68f946a0bdd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:1d319c84ac72796d8be866dd74660aa65f069c09d3f83bcac3cfc9abe0e6ee94
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:1b4dab60fe5aac092e151bd15de6369ce02c4c9cb8c85256f73900022e169d65
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:5f08c83c7c675a46d88f0c8b06e2fb140d0053cb5607aada75f7327393190e6c