Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
alpine 3.24
Tags:

22-alpine-sfw-dev, 22-alpine3.24-sfw-dev, 22.23-alpine-sfw-dev, 22.23-alpine3.24-sfw-dev, 22.23.3-alpine-sfw-dev, 22.23.3-alpine3.24-sfw-dev

Index digest:

sha256:82396cdb71bf33ba06643392406b3d945f350376d9b568175352c88e7e665cc2

Manifest digest:

sha256:56a402a50f666056aa6ead89142966467ebbcbc7ed851247c770b19ec49d007f

Size

84.53 MB

Last pushed

5 hours ago

Vulnerabilities

0
4
7
1
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:38a7d4b16e0d5860175897ac68b48c86a2a6f83c9877c16a1bac678ac5a33fc3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:8478547bf0cf620fc6c0b7ff001be4bb7b8860195a51ea26cb3c9e23283f3f67
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:f394a5c486229445fb7707227722a870b6fe36922c5b327ae37992c4805dc140
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:a9c0ae8c37f0c15b77c2dcbec35fef565647fbf81b51d987e428b713eff90a64
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:8c2aeffaa2196941ef8e1173f0355ffe433a266c473973c0253ce7f2cd1da193
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:d719e6f87e338695838cf34def2c061eecc0833ed86e0a47c772b7beb8afdb6b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:71fc9f73ee0a397df1e5f10d47f5ea0dca381cb02e4ef59b331856a60de25bbf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:f18ca5110436f5c0d1260a9625282b6b4374a2da088a7d0476853a9cc1a71a56
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:afa8c226914a38fef08dc9d2d7ed1020881aa96f51cac6a50df052fb16b6f549
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:3fe8a3f40c09f2748fc514247818064c7bc1971c8a336e10514346b2be74d283
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:cf8054af0a5b4261114333d196e80e0cce84ab2a7a39086e4a661dc7438507ae
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:c498718fc5b42c2d4f3b641a12239a8f31f9116a9636d36c481eb1f76853a307
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:1554d84d09c6faa53e12e6b46c14e337055dc25420f83a547cd061e63d8c28eb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:910ecda441c44e53c21b99672e1652860e332d97399d156e728ec10b0c7d3f05