Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
alpine 3.24
Tags:

22-alpine-sfw-ent-dev, 22-alpine3.24-sfw-ent-dev, 22.23-alpine-sfw-ent-dev, 22.23-alpine3.24-sfw-ent-dev, 22.23.3-alpine-sfw-ent-dev, 22.23.3-alpine3.24-sfw-ent-dev

Index digest:

sha256:8d143171941429c61412e303e5c4a503fdfe81bb0be08d47ffa4c1369a2f7ead

Manifest digest:

sha256:e66497bf09a8d1c04aa56ff7f583615081ad95d98f21ce847fbf24c640758f59

Size

88.20 MB

Last pushed

5 hours ago

Vulnerabilities

0
4
7
1
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:71c06c7787829c2b7fe77cde55813fdf7cb8bd372c0467970dd4c54e9029fa05
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:3d35f00f226c16a727e2aab3571306a83fe5f0abe75c4ff9a51eb74fe665797b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:bab609f5aeaba06aa7759da36cf163fff0259914fa9febc220ee0d6003e682f5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:c5428ad1c0c33c01fead17820d86a0782f811c8566bd434bbcb0a3ea11fa63d0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:bb6e58abd314c0e5639755badba480248b7ec3995b644e42689baf90f7080673
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:83edbeaf8941ca8bb38b92b7390337577688113b626ab98dc7f6ff87658893e7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:0c8f577bfbfe16260bffa4bbbc0d6d7d1c8dfaadfcb1559b1549a5cd33d20bbe
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:d1513d46b52545f731ba51d3e00ff24541242b845fa967cced07846fd82fe454
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:416d47dbfdca419896a7094cd85af6ca4e31e56ed0b615e43948c5b8b04cb803
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:000890137d67e1d517cf20c43b15e9bde41223c8e9a896b6865971bc946b88a8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:7a708393c2879e9636665a959bf04e959d5976ebb27310c05695859213a6a009
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:5d0f1f73038b0c5f9c8cd80179aa8dc8a89950267c790505d4115e499c40e853
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:9ee9fab13ce1c8101ce4ff6f6a58d109b714ab260bcf6eeaee8f7fc6ab5d60c6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:53950393b68a1c69012ab6d5df91f8adc4c968b35c6ca8f3844955c320b19812
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:d5502d1790392cd7e50a176abe095ba5a658a7a5654b11861a3a55ef2d9808f4