Sign inSign up
Node.js

dhi.io/node

Node.js 26.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

26-alpine-fips, 26-alpine3.24-fips, 26.10-alpine-fips, 26.10-alpine3.24-fips, 26.10.0-alpine-fips, 26.10.0-alpine3.24-fips

Index digest:

sha256:e0f10135e866d0aa0d324f86232e517bca515da436cb4e52aeccc9ac9b553861

Manifest digest:

sha256:560d4d6a071ca79feb449e07d676abdf579e60842ab11251c261e06143b9d07e

Size

42.29 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:1e020c858ce2a605f6f1ad092604942f97fb3c712d31bc0ee3b6c6f3b44a92c3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:5ba580d52680720302d4ed991fafc92625e165a79ef8ceb67fa001d4963ae665
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:0b50fddf46868e1e2c723f5beda34592a584bd4533b8acba1afb442c76128fd6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:d6337d3b3fb086e8dba73398e673ba26bbd51f0a02c738a0dad1d47f6ddeebb4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:2f28b6d552d3b11e9d6b537a9f65020b00ed22297ad20b6d785df6d148a12620
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:64f4b229cab7fcc69046d9e538b5901c58d53f434445ef306edf7bbf8f37e3ed
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:542363f1676e10c0a332f5e358d20e11bcb14a724fcfd4210defa62d94714327
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:86ee87079264b5a50e2dd6dcee580ebd9a998576cc8f3c3602de5e357673f651
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:034f0a62abb7ca7ffb218b3b6da39ef76b20364d84b6187265da74bcfb3f0f41
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:2a418aad3b79508c5ad4dd85e713f2f2324aabac63781d204177f45ab348c4dd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:60acfe371c3b4e42f669b37d9b9b3fb5dfee1231d4dd9e3f8f900d4f70119233
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:1dd275ee7fac9a8d57239f48762d8645b94bdc65517d2b181e11fa7cdbd92c43
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:64f80692f50afc2d7072b23af7c07bebcd52fc6276af53c6a2ab713007395f29
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:79431cf9c8c70fe9e24da75ca6a7d6a6c547667c367392b3e08d36071a8cdb1a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:5af7f429ace49c66fb1cc389527e312d181655c4e03491c7c87ba33f3e0f0510
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:4a9edebd96d255398203a9c9b9955a723e2421ce94ec05ed54d6f7b78368d6e7