Sign inSign up
Node.js

dhi.io/node

Node.js 26.x

CIS
linux/amd64
debian 13
Tags:

26, 26-debian, 26-debian13, 26.10, 26.10-debian, 26.10-debian13, 26.10.0, 26.10.0-0, 26.10.0-0-debian, 26.10.0-0-debian13, 26.10.0-debian, 26.10.0-debian13

Index digest:

sha256:29d425d096403cca2750ee83fa31e4a6f25a73ea78089382578053d1682afaff

Manifest digest:

sha256:f2ea3b7ed4c83234ae0f8cb8f1dd896285b0029648625c24f3d35c5e747ffed5

Size

42.44 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:626fb65bb2c8622415cb170e6dd0206f8f46dc14fec83892a0f93b52bb76f058
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:114d1bfe6c29f24bdad5d6c43a6e916f5161caeb1b24f46f6f00373b93b3c967
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:0deceb8c99b09f076f723840712d84994a8ea12c767ec38dc633eec6c3a42cc5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:e84aabd3d8d4dcd6806efa09aab9ce06fd390e87ab5f26e2361dc2a112e5bdc7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:2b81d730d4ef208c30ea62c012bb0ce017b2e78ceb3b57acc0d165ed302f2a4a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:8a146ed26e7679827bc39f7f6346ef1bc76ba89b44d2749dc2259bb34f4f28d1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:1b61f03d2ab096e1ce6514ab9529eab4eb337d9055471bdf004b89779c55d165
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:1aac147e668a2661cb51999c974acf69b182f2900f44a3c921b63a8b1c6f7874
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:76b4026cc94bc45f87fa13b33d4af06891b5f6840399354f99440f73cca4620b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:60c7bfc45ee384548bd088cb27c485faf748e382bd7e67868569b87f4ec9d296
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:ac0f20f3fd2311b496058a5b2329dfc2939b721714af80515a48e74689b3b66e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:5159e3f37e362f1ac8dea93813938af686c41dc4eb8615303c848b658ace48cc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:35f05ab8fea4c0f16af648d20715ffdf20d9a92fb0e2c2153679fba9839a48ae
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:162e66c9044bae7f6454630043d2fe5c61d8112eaa278e96f2623b10e221b75b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:4bec5f0b00bbe6c14855b542c79756f9c4051d127d4e6e37bb3309a5e26b6ff0