Sign inSign up
Node.js

dhi.io/node

Node.js 24.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
alpine 3.23
Tags:

24-alpine3.23-sfw-ent-dev, 24.21-alpine3.23-sfw-ent-dev, 24.21.0-alpine3.23-sfw-ent-dev

Index digest:

sha256:8802b0e018b828da7cb8f9fe730ea3d299b7854dac4c3c823a60797a7daede6f

Manifest digest:

sha256:af2c8f2eb4d0a8d36342162182e18d94df60d4865b19ac3d0b59fb9b91156bd7

Size

88.28 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-alpine3.23-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-alpine3.23-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:df5ad73f6ac59dae9b58fdb5c126d7cb1865f166913cfb2ed118bc637f0c6b98
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:aec550e06dcd59dc64a5c27b195d4f1d0cb4ea03ad89ab07c7fb3cd57b61d902
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:e28becee7d3aa226fd7ad8eaf6fe9322e6928bec5d9966b528cc14d1af47d647
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:ae0478de407ae7b524dc210d1ed5536c440849b8a998b8706110f35640cdd29c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:3c50af6b77ec9cb8e0483b88fd496e2debe78bb6b8ba6c88ca9b6c61cceada8e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:8c9b52ef0fa6f4ac217cabccbd53d9dae93f52fb02fd7ae14bbf67e080d44368
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:955eb3068141413edc18b1ffcda3bf6bd225ad0dba3ddb4780d94f85a2bc8175
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:6ba8e4ac142d127ddd914b098895ea00cc6099989c757314460e66ae0597e0d7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:1e48823982a5245a66d75b3976229f779e24e5c56cc11d1e70bdd87113e4e2e2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:7e0f1df6b331a1625a97d250420acfeb92f749a636f457f5723a4be3124283c9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:367cb52b97473727abceed9e9ee9896f441cfc6a0fb44713cca107d263d963bf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:2d2e61d53e75a12226be5d9696cf64a87c0fb3959f5262e798d0103f28315f45
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:d816e3b6eb40280885d0d7aedc7f8d0f5ad4b1b9cfdf329ecba14a24c6a231b5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:4d9b8e1bdf19da3bd0ee7f61a2e2b8a8004c71619b46ef08841e704708326604