Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
alpine 3.24
Tags:

22-alpine-sfw-ent-dev, 22-alpine3.24-sfw-ent-dev, 22.23-alpine-sfw-ent-dev, 22.23-alpine3.24-sfw-ent-dev, 22.23.2-alpine-sfw-ent-dev, 22.23.2-alpine3.24-sfw-ent-dev

Index digest:

sha256:6c1bc565cee129d22e8853ba96156babc08f9a6c15d8ac8fe95516f53f957640

Manifest digest:

sha256:a40cc1b8d43e66893c8d1c916cddd1a734a205f4f0cacc8c49c6bcf9a3aab853

Size

87.70 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:e6f650f31a07d89bdd9dd5fc9a5fc209c0f3c8b87a3f8da6ee2c26f489eab9a3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:94f3ea9dde10bfb53d5c3771a5ef7e516dc640cf0546f0bc196da7ed904daaf0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:fb56a74665737cd56f0f4d93516da3b7f40c69e05c1e2763470bdc71c209e4a2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:477b29fa5bb73fe177d400f69c79d9c3cff94397459aab7a878ddafc4dcfa5b1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:95042ea0d273f1eec642be9bdc1c2cc4eb92be8689328c837287f7f51c6772fb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:3458f5d02ca96b5ebfb0794b603bfd85d8ee6a5e3b7b0cf7a469e390dc3b0650
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:e16620ecc0fdf70ea91323f885ef1b48358c6d0a91569d5d1f395aa88b64c764
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:7074995f6933e9fdd7c2af8f97d8615bff7bde8b43e592e22fbea4fbbc410d1d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:5ba60e107b0c74746ada4814953aa9dbc21510cd688e39487c7339905661fb7c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:627d314c77cbc1bcf70dc86ea6ba4ffe308b4d125ce2279b21440471e766ab74
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:aebedccc9394b7729b6cbab0b9b18b2103c75180a256eb79540ce581bdc639e4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:b0bce09b080e31559a700db24093e4e2c5beffc698f257af25f1f539cbce40c4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:95645348a7d62b3900731173a892a8725ba170f5189fa32c89513e7265b6bc65
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:0f964e96db7b12c41c73007ecb92947fde05378e8ddf2b660b8909332d77e936
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:95377039f31c8fdacb1e03d20bf3da2dfb214e4cdce1b4927db2c1c8acc9e028