Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
alpine 3.24
Tags:

22-alpine-sfw-dev, 22-alpine3.24-sfw-dev, 22.23-alpine-sfw-dev, 22.23-alpine3.24-sfw-dev, 22.23.3-alpine-sfw-dev, 22.23.3-alpine3.24-sfw-dev

Index digest:

sha256:a54e60c44b25cf78779c964059550480a1f7b174e65e882f37a52d84f09d62f6

Manifest digest:

sha256:83d093aaa263e378d8264307aa63f16ac30d56e35683b4c4ff3da91f3983c228

Size

84.53 MB

Last pushed

23 hours ago

Vulnerabilities

0
4
7
1
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:7da8c48c8148c3188770aee4260d5a6bbb7fd75cc6aa67a5d61c6edbea175435
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:e1bfd22ad8f7f25288f34ca78f47b730dfdd688d71b5d45e4719c8e175ae972b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:77aac825230c7a7b735b82e13705ca0e5edb3d3fdc6fb1c9ed992f246ab87727
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:b6d58a30c55376022a0e3e65ed40c56e1b4c0f8ed029e4e1da4265519a4f1c4a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:92aa731bc383a6be71c65a17802f055a920ba813b4c35eb52607b8743f95c38f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:89ff403c5405821420965cfdf057496998f7f0fa68a039caf783cf0a3601b2a6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:bbfa1ba091bb1b950fb526e59f3489255d5e905be63c55fd87e357ee67e0c7fd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:8c47c2dbe8796959be2415eeedd5d1d2fa39ea02f6a3ec67c25381cf91690815
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:2dd55d0c8e431669eaeecf71c80f0d5a8bf3cecd7bf35da605eac3e7cc2c7aca
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:3d6832875935a5f3de1198d264c4d1b94c69721133c6f20c986977aea2a125d2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:b36079d47c7e7d62071229d8767546eb2db2264d3c74a3e246aa125147f67a3b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:e27a820a9e3ef28a26d61cd0b8f42d3d10d5408743d651b780457a4495460dd2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:15d6e173ec037683ba3254a1d8ef4dbfb8e6cd06df6a0e61622d144f7ece0dab
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:fc2b5169bcb3bb252674352b14a70a606eb08b9c7a7ec971788487458885f874