Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
alpine 3.24
Tags:

22-alpine-sfw-ent-dev, 22-alpine3.24-sfw-ent-dev, 22.23-alpine-sfw-ent-dev, 22.23-alpine3.24-sfw-ent-dev, 22.23.2-alpine-sfw-ent-dev, 22.23.2-alpine3.24-sfw-ent-dev

Index digest:

sha256:4a6968d0336ef6fbca9cee37286c5eda95309b9c83c0558c8227f026c752837c

Manifest digest:

sha256:480cf03419a4d97caf1659e6f83d592f410e522eb6d8629ae42d1e7e1f8649c1

Size

87.71 MB

Last pushed

3 days ago

Vulnerabilities

0
0
1
2
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:0d6442f6ab6f28eac49b3f33cd689c083bde0a021d9dd4f4d8b050eb3e3e5441
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:247a5de4d2f74b9b2e13bcfb76c03bdc57f216dea29d7c58f0986c7a065946ef
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:1d50722e9ccd597c5ba9cfcfb431e9b1b4295130cdb54ab1e9d954b48f8fef44
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:3d94cda034cbee0433bb51bc173a595469e1c0b7d54900c67062cccd45b5961e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:907f247caf232139707f875c790d6d625ba7e4f315528ced8d0bec74e37b41f6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:88d140d2cd510549ced4e16805552a74e117c5f5a59f416fafa3eaabf1ef739d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:d4a5597174874fe6b37d3bb63d46b40cd131d8bf9ab778d3a53e2ad576845877
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:0045cb65355156ce4b2f76ed861b136869b791680d6bf9b79f86e11c1458d88f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:f62c73797bb974414df97bba3230e7385ef30005b80e0609afa7045cff00aed4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:9eea7b06aaad57d6c23fd83b724355f701cdae23e4d2970fe0e98db1fc847b4f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:dccc8090cc94eaa5fe8dcf2b4c6c65a21bb8bff5d4c501d857ab50ca1c9e43d3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:67b064fd144e75c6d6bb0694cbc75c52b91c6a30145bc4b758a8845eb646dd02
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:469858c35ae997ad3519bb1860142b384ff3ac15a6b4be4f7f5e6b98c55dea1c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:e6a16fa5f5cc025e44ae84181119bfd4d4080b287e5e5450d64a4a6cf76dd23f