Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
alpine 3.24
Tags:

22-alpine-sfw-dev, 22-alpine3.24-sfw-dev, 22.23-alpine-sfw-dev, 22.23-alpine3.24-sfw-dev, 22.23.3-alpine-sfw-dev, 22.23.3-alpine3.24-sfw-dev

Index digest:

sha256:ec8ecfd19ddfba8e46b7f6ac037dfae0ad133487951a09b255580a9b29d09bb6

Manifest digest:

sha256:028f51d31536fdf9b3370969d06e3b7cb2ed9de000fe67e2cbc2bc14618e42fd

Size

84.53 MB

Last pushed

17 hours ago

Vulnerabilities

0
4
6
1
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:0ce939356235d090148c62003fa8302bc7af8acd5907423d473f9b816b3ab8ba
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:d4fad692a46592aee7e8d15cd2b6cbc2483990727b161c2b271d4ae7a994d3d6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:61b4a37f01f81ecb700867d5caabfd436c4c8ef2be0aaab8e3d132ca502ddd34
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:22dfcaf2c03c995effdb3ff8faaabc012847242827f28ca03c5f8315d27c9605
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:9b76ce30d2fbcdc6c38f21721961d827776d1255604b55d74699f4c936786b50
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:79108a73b98da3ca2ea17151672c146b9fe57a9567a12162f78766f1c9bd11a2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:9cb694217396fec8284f27f0da8717884410244adab468db10a0296e72d55dc9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:e0b84daa2ba91181061459cf396c58320145d58bfb3859934241b9c2378cc8b5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:8b2bed2c24b1d07d5f16ff888a4151d6450478f27f498d68fc90124da1bec065
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:ebb49d752c575b2dac6a48eeb9729d4bbff980220372b2d79b0f0e4c0f279c43
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:13e9f2e455af432b579e80714323ae6ca06171cd10c076f8bc1bfa2dcf91d4bd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:1dba3b6a2d76e31e90b2514766cc2cb08fb0c1cf0e548f349c5915f77d3b231c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:3cb4a51d96226fae6366b32e2d25cc1ec43c7865b037294198f75186b55ef101
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:ecbabcaec8926939cea7c6e6fef20158107ae08f9fa9d4020c5a6b7b3053937e