Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (dev)

CIS
linux/amd64
debian 13
Tags:

22-debian-dev, 22-debian13-dev, 22-dev, 22.23-debian-dev, 22.23-debian13-dev, 22.23-dev, 22.23.3-0-debian-dev, 22.23.3-0-debian13-dev, 22.23.3-0-dev, 22.23.3-debian-dev, 22.23.3-debian13-dev, 22.23.3-dev

Index digest:

sha256:9c4e351af70b0f77be69dbb30c917502638a8a8a5da1330517c97be1ab6b9160

Manifest digest:

sha256:269d826f6a979b781aae23a5ca2d8db99892abfb511b7b98335624f250354129

Size

79.70 MB

Last pushed

5 hours ago

Vulnerabilities

0
4
8
12
1

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:15b25c2c1bd9db098e893a0b102cef93c1bf0938a311abf5ad4bb39302f01c89
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:dc68e03dcabd5cb588714601287158161a2cb3bb456a696cc50a6b067ad09261
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:14bbfe41d5c27fcfe850d1feb1b4f4e801f3df23bcb5595f561a82f3fd21fd17
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:a6f61e9900ea4f1eb6ed2ec40eafbbe9cdd553aa0e7f20b15e0cefa9bbc0c56e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:3cd7c3a23d60eb289b525d8dd666699de71acaa1c378bed5926261b9571cf97f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:6d5ba4a7bc0169f8ce09c641f04ce1a01946ee9bc9543d46a20e03909a5db83e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:a8e79977de4cfb76e99aebc00a2687ba6bf0ae288e021dae2600437cb6087e82
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:8e547ce58cd6c78eb4f00e26a5176a31c7580f778d6b1eab540648b78d031807
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:18214ef112bc0a4071d34d21be515e31ac85573c75a3c32e382eb725a586fab1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:57ed85f3d6a9f39566afae550c53badfdf7c804912c6eb50a5fdae0c080e4feb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:df2b52ddfcfcc018d753e0cd0cac18f60acb95fc7f244cdd83c9777fe43bf0e6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:c67fce53c3f8a74bcffa6d9c32771c181a67d4ded5f8e808eddc4882cb742c32
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:13393bd6f55d819c286e9e760e64f9e009daf096ae62aa71f1a089e553e92310
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:950e71fa7232f6f16511eb2a3cfa280b9fa1906862269e5b0d18b84eb8c6a2d6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:2e8a35c8da456e9fb6b255b9832931f249be7a1d4cfbfe5067d58734ae0fb353