Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
alpine 3.24
Tags:

22-alpine-sfw-ent-dev, 22-alpine3.24-sfw-ent-dev, 22.23-alpine-sfw-ent-dev, 22.23-alpine3.24-sfw-ent-dev, 22.23.3-alpine-sfw-ent-dev, 22.23.3-alpine3.24-sfw-ent-dev

Index digest:

sha256:dcc1ff26e9a387d60463968db4d19c6e0c6f5c82982a08e449084922f42095c1

Manifest digest:

sha256:761368701005d512d62c69c5cf2e2b41799089537a86e44190e329d829da8143

Size

88.20 MB

Last pushed

4 days ago

Vulnerabilities

0
6
7
1
1

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:da700d8d7922c74871bcb162857d5d5156613eb59bd2ab660de77381cb98f4d1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:61cc13c60fda4f9937430d6480ac0ddfd71da678ac2978c4241dd814e0b41071
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:07df5dac5e2a10b7b854974bc9dd290e36788b5d2a9fc5e018b584283df9fc99
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:966e1f6b3b15e2df2ece64238677c22a265fe39fc174ec35916f137c9b64658a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:22cfff5b64fbf20efd58174c9c16eec5c94cbe35bb3fa4217250843615e14f0e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:58a7a87c804aa114aa9c09863a37b7c375ecf4cb845a7f4eec101fd78db66660
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:d969a7a9a4e8059224f2e049fe900051cc5a96ddbfe091a9bf569d988326650b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:b22516ac2039b82cc086d595b435f4e3ee27368fe6a8382ca4247ebbb9abc6d5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:a3c6d39370f5ba4032dcf17e03a62e256f61857ac8b866e2176d09ed3e20d585
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:c6b24bce3c04dc45e2a73cf9059ffa8b43f0d4b66d3bebbefa4f387d9823f16e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:e52dd08cd65c2b5db3fc2011e64a9ee8b13224888d672bdd0271e72cf150a524
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:77b50c7d8afaee375d8501f1b0d914559d875f66744f2239f9abb606f2375a86
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:ff552d4b922c543f42b512f4be0fde1d815dc59049e8210957468dd2a53dbc55
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:ddfe2f6b4b9cccb6435fcf20695a9b54185067aab3f20348ef5c705f12eadbbc