Sign inSign up
Node.js

dhi.io/node

Node.js 26.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
alpine 3.24
Tags:

26-alpine-sfw-ent-dev, 26-alpine3.24-sfw-ent-dev, 26.11-alpine-sfw-ent-dev, 26.11-alpine3.24-sfw-ent-dev, 26.11.1-alpine-sfw-ent-dev, 26.11.1-alpine3.24-sfw-ent-dev

Index digest:

sha256:07ed242ce8e6f81822b25d1993165b23a0fc09f20bbe2db974ad31813429cb4f

Manifest digest:

sha256:c7bfa27f90b2978c183ff9b26bb02c632afb34ff699e69af786b77adb4e68ab5

Size

91.78 MB

Last pushed

18 hours ago

Vulnerabilities

0
4
7
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-alpine-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-alpine-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:fd4938b2fbb05b472b32728f375d6edfc7005a89bca861bb0d42e284b1a5c3a1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:58575c62df79b148b667fbd9c69c841c44034bfaff79a503548939d07b8c0282
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:f0a416d7217f3dd20653a53de3696634f06d8076ecddd8ba6a7afd2784cd3f27
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:1e0400b7b3511dd0604fb293980b0f63985fd0627df07f02d0137e6451aceb7b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:4e975babcfa7c63ea5bda29b77b5e70f4e449c999c07b604480a9ec773d4e54d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:5681b162716e90e3378528127b093b0c0b052a4659288e9777d237d8c65c40ed
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:5b2876882afbf2965ddae48e244f6ca10c06659c8c827b62993f2ee01606588c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:466f3523803ddc3faa33cef02d70997ce62373aad68dd0881a7ec581d2ddec33
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:0746d5a59969064f3562d532dbe0bdcf31aaca820551787120900278fb188d80
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:1b4d11cc232a0b4f20bfb63b9f3b33e61672300595df059150206f28f6fa0b8f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:786f2a5797011abe79f365848537d8b56d53f967e39e1369badb4ef6aefee596
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:fbb57c76cc290366b6f42d1f210e4489303bf7110050394913929190c025c807
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:ac6cf6092b474b847d5997219644659c77f749a888669ee137a80d68bd699df7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:a5d240d0d5eb681c2470489540d52b508295ea296b54dde658ab02873743bd52
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:31f1224f5c88a924b5b57036ff21b7268d7d355654c5736b6385a363df63ae8d