Sign inSign up
Node.js

dhi.io/node

Node.js 26.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

26-alpine3.23-fips-dev, 26.10-alpine3.23-fips-dev, 26.10.0-alpine3.23-fips-dev

Index digest:

sha256:91a799c8936462f8f06b04094bb558592b64a33a5980b086c6894e9e245b1a5a

Manifest digest:

sha256:c416f4feb123b32215a7ef8f8d15e272c2a90a196b85e3cb54200aa31da5295a

Size

51.05 MB

Last pushed

19 hours ago

Vulnerabilities

0
4
6
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:530152c5d7cc206ba6bec895cf63bcedc786728faa4fa2f3d88a492aaf8ea1f6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:8f56988a6530d8582fc1d2fad4879c16c89707ecc8927b094dd1907b988a9ab4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:054b345d3ea707499ffbfedf24fa7cf510a572d9217754ac9f728b47307cc8c9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:af5f361b1f2ada4f3e03745cef51adb8268db40520efc2cd059f5b55e9c12a1f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:530d770d04b87b7c96d053d35cbd861f39d36d021cf7776eb3142635060dea6c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:f08ee61a0738c9ea063d8c1851ea248e436a48bb49644275211ccfb930f6f25f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:dc123f0343c653f38c4a784f5e968ea41e328dd1ad6b8ae9146a97a71a436e25
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:0d749520199d32f0d337d876b1cafa27c7870c8cbbd7b1fd604f09ffc37fa84e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:33fb916ce71ca115aaddb52b676338d9206e15f0b96a2b3563b7ab4ef92bfff7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:900f11050328b26f27eb305509821757bc64cacea0ab52bf90e440f94b4d0916
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:77b00e4c13bbaf4abf2e441c36c2d959a4b4127b6e5c0e4c1a9d1cb75bb5acba
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:848e9376ac8a1861b161fdd8f7de3d62e71319328c0b4a6a49623c0180e2e16d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:5da55ccb88fbabe7b79fc41c86df308644bb0ca991eda95d868ae2f431b14900
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:43b11fbc5aad13ca81128108c3480ef37a080f5b1bf26e379918eea8e7ebc7f8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:4c65d074c699e37cc03f85877022cee6f83656a2a63248e5ff46c4bc06c28987
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:7f50bc803d07fbee5efd0623abc884759619912cece4878cf0b7a7fc4a531c2d