Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
alpine 3.24
Tags:

22-alpine-sfw-dev, 22-alpine3.24-sfw-dev, 22.23-alpine-sfw-dev, 22.23-alpine3.24-sfw-dev, 22.23.3-alpine-sfw-dev, 22.23.3-alpine3.24-sfw-dev

Index digest:

sha256:961926aab1168a0c4d5fa1cbe2dd828b363675621e9de27223bbf2839ecd2c04

Manifest digest:

sha256:d5b3e5f3c7982f8f3889d628a5d1a7b1b49fedf0550911b77cce6e4733db2b30

Size

84.53 MB

Last pushed

3 hours ago

Vulnerabilities

0
4
7
1
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:5763d53377668ba958c8ea94876fa78a03cf85ac3708c051fa3e7e02413ff49f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:6037c80a51615ce8738f88e2b4c351a579acea6f72df6cea8e3f3f9bd180364e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:309db87f7b5f2508db12308734f92fad5a6a9cfad9197e569e7f4a9ebaa77b97
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:3ff01b329ca130bd0971ef1ba5874c811b8314d0f3058834288e12da7c2b7884
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:9811e5df98191a48d9da204db219ab6b4d4d97a2242ac37865c2616fda8f957a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:60859772e3b1b0b2ae96afc7b1871b5f70f7911ace85fdbf0fecf11faddbcabd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:99a7a52f4978b11d82d7cb9515c4c7653b02e782b14e9a2e408bf18705b0ea8f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:4910cc31598245bb7455ccc59fc2a024568f87270bd6e2a369da221fa1a0ebc3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:6217a48089677499b983e6f399a4ece0021bd6f1f1a8e199d40974409a19c0a1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:0d39aca632c6cc99b38fbf25947454773802bc5f00d2866d494ff9d7b5c39229
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:8e10b83d0a4fccda848f085e8036d548ef1de148ffc93aab7619ba0337671094
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:6adac2b097848de706fe2b2a7c239408cfc77a870d076ae3ff22001aa73c0a34
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:2176b2f8a6a3d1acbf83d365c5d817e5e1e2d9d96a89eea82219ba83cccea0fc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:17a606c876b2abe57b6f8af9f04156c0a4c568508bf06a6d29f20203539799db
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:55cec0c21c64c250a5014ddf9f6ab04b2b49059feaa854c10cce0d4df68ece60