Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
alpine 3.24
Tags:

22-alpine-sfw-ent-dev, 22-alpine3.24-sfw-ent-dev, 22.23-alpine-sfw-ent-dev, 22.23-alpine3.24-sfw-ent-dev, 22.23.3-alpine-sfw-ent-dev, 22.23.3-alpine3.24-sfw-ent-dev

Index digest:

sha256:1476361f6fa14a4789849bfe72ba3eb079f994d9ea23e334eaa637c561eb6267

Manifest digest:

sha256:0c6c51b279b171c098b153e3d46588b6408ba737bc854b8705b7096ab57dbf02

Size

88.20 MB

Last pushed

7 hours ago

Vulnerabilities

0
4
7
1
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:5a5c2f68b0e91bb48934373561a8adfc015fae20aa178898859ee0512a4fe681
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:6efef7d20a9097a6c1d292ac8a8e3abaab25b692f6efbf7fdb3442979a478ae4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:2888e13c31c850056aa417dae25b311e7476b46e81dd7ef98fe22b660bb10d74
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:dc1418bf960f2748f47118a2f694b847e583e1a67a3fcbc4f96445570bd7525c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:12d3d0782fd031940a55d6060a81de47f350a815dadb7fdf5d7935e815b67c9e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:c6b91c180f4c3aeb89f9aec5cda141c89c8d14323930b3b0bfe7f64aa1657e95
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:b282bf3b66ceb2347b5a6b8c001f34fcd776fa243ab0f7a9a7e17649c7f2d4d5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:49d9c4fe35dd87df3e7bc8b8e467ea87a94bacc4ef8d0fd9ae30a8b678483929
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:c0f883b5d802d3d6d99d6aa34d2142657f66a4ca99233668aa42f4a9feeb2428
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:d89d814dc301a3cb2ddd9c2923dc8ecdae3c5001974845cbab83f489325c2289
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:fbe122658eab997c4da5965c114c07952705ae8ced698a16006a4c9a910a3214
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:3b3fbfe958f4282dfec8a4bab88689c7a4bed28f3569dbc375acedb08feba31c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:6f601af5b7b0433d2d048501d41cd156f077aed5d97f957c9005f64e2e6706a0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:b47cc5167634e2b4a5b3d6e55666c259c180f442989a53414e6255d874cd16c5