Sign inSign up
Node.js

dhi.io/node

Node.js 26.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

26-alpine3.23-fips-dev, 26.9-alpine3.23-fips-dev, 26.9.0-alpine3.23-fips-dev

Index digest:

sha256:ad3bf550ae80756eb25474997153179987984eb6fc41e0aca27cf793f0fdc69b

Manifest digest:

sha256:c2eac338d8fc27d032f57fea4acda790e3b38e4645a4b047b53a4218681d8be9

Size

50.93 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:7038a0bd59a2fcc536c4ede9263c091af1f3d9d5f3e0d95dd7752ba00f4de179
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:e2a62d025a8cd6ca9a91a097bf0b463ab339e0861ecff7981f60441bdf40e0b4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:8d4f5102e6626088ecf07e658b96bf0acf2989339cc7bbd785760e1412ae8b69
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:38eb89d88cfd4f3ec8e9ce015b178e72d80228f2c3bb654add56716a870459d2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:7e1d25775235545130144a1307f5ad285078f8763903f103ce65fd16eaf31586
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:1017a893d38617822fc8a6f9a17b29332f795ca3f6a45aedecf080401937f425
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:b0dc919563e9ea852434495520f2070ab197f20e1c8f3c5fb44f9f46e7a16d63
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:ebb66f0029bb33f09cf7045e0579d9a4915a1ec048abe815b44facde8da81c1a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:ce6037080b3fa48ee16620a021c98d594313a9f2a9c14b156a14b4ef181b4e21
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:9257a69b86989f274b8ad7381d1ac4c196767b4773d85b917669c1bc552acf71
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:dc4553a07881bf10887e333e329237274ed12252cbfe654c736b3e29cb75fc48
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:7d7de80069c0d1266f70cc50cd3142c051ebd66d4cdba8a7f272bb16c9ef45cc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:0d5194676cc5884dc89d71f4204c38dfdf8846b234a106f08d2f222316bb8622
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:c145efa3aaba75b9d19ffc51eed24f16c88cd05393688251ca0b29017bf5029d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:e10ad48232f3d63f987f3c6aee5a6007c39671e9b659089fe3f04fc449e18d82
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:53b3b0e603ae052064edc96a94c320aefc56b9d194298c555a0fe3bd3173cab2