Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
alpine 3.23
Tags:

22-alpine3.23-sfw-ent-dev, 22.23-alpine3.23-sfw-ent-dev, 22.23.3-alpine3.23-sfw-ent-dev

Index digest:

sha256:2a2e8a2880a778406c29f0d4e9bc600d8ed341b279e1783f06d8a24fc2017984

Manifest digest:

sha256:b018d2240f7ecece178e08b733b5e517743bdf2026e9e7268105e9aed246be2e

Size

88.22 MB

Last pushed

1 hour ago

Vulnerabilities

0
4
6
1
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine3.23-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine3.23-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:c694503572c0f06e25b7ac34982c740a395734810fae47fab19ef8a2cdf81dc9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:d622b8d843634d569d12645e9e7fbc4507996a669ec5d98b12eb9e73fca655b5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:5e2c9b16f06598172ecf12686ece4af27179058eb58fa51edf678a217b2e2f65
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:9e802a4b7e642d2a417704098774756f09343fa7d912b4a44a2e991769d986e1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:3d4046e169b4a2d668497f2f0986f2ea5fd75fb15bb58bc2405008704335835d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:6f8b9ec6ab76b1274a3f48b334e799f09894cf24dea364769d15463e8bf391c6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:b987ce3a241afdd7efb4c5d219542ca82667c899da89ae06d96a3a6df4f8f592
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:d0d4e946d6a6c9572647e122bfb944f55e55b51c809030c2e0a4e92051e6383c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:f4ff598ad2bfb6d50a3fec723928cd708f21eb4ce2ce71490543753472bdb61b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:a7e0e88674f1d3133f8781ff9bf7cf7b03e04194b2435252120c49a20dcfac77
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:7ff40f5887b89c54c361d4a0dc4a6d6b8a9cef0dbbb868e897284e8b164a3aea
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:96bd813e8cafd8d9f40d8e3e4203d86962196475d2f76fcb3056656f60b30d7d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:6e62c48d00737339205d7d2f034f169519deee3de9fad13ef53edc35abb6b550
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:43a4e5826fd26eebf5d29c1c2efd5719ff755cb89105fe43b935afde98f78084