Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (dev)

CIS
linux/amd64
debian 13
Tags:

22-debian-dev, 22-debian13-dev, 22-dev, 22.23-debian-dev, 22.23-debian13-dev, 22.23-dev, 22.23.3-0-debian-dev, 22.23.3-0-debian13-dev, 22.23.3-0-dev, 22.23.3-debian-dev, 22.23.3-debian13-dev, 22.23.3-dev

Index digest:

sha256:b5c3d3f90e83e3ca705eace5128e1233cb891cf936db3cadcbf1a5d4a186fff3

Manifest digest:

sha256:72085a614cab063fa4ace9c54ef0033f2d02916bf33ef1e1f907030f2d257c1a

Size

79.70 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:135ececac42dc2ce7fceca0ef0c556767950300e4e1a9de778660ce5e058ec12
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:4523d6dfbe44f8aca75bfc07a726d198a6a621025ae0c57711eef8d237e863ac
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:f90dd0995592025a11e40e21a4b37cc479c4d67c5930f1dd43986d8502efcb9e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:58be60229e13ed03c012986f74680480c62caae234cf14266b0803b083c74aba
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:c6b329b739a2ba58bfbbbf6ebf368f244af81f0c3aa950e1427fc28208124217
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:16670047b09de2dc185473247322629db2ba981caafdda2b5ab85824b72b8557
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:5fbed82d9bd916001db15bb8f988e5bfd52c363745b54e39cd6757c18d7efbf1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:ec50f21f8ea11ed3a4040e3a3920fde40f800986f91a453ad9e9a06377c2c2e5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:d99fd0fa03815a23ca783f290ec9731e46fcadad7cccea587e1011fa8023c04d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:044c764ff185af592a9bcff426e4675443045c8bf304001b278b25cb8c3b5fcd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:e57cec1decb00d6e5281aa57a85a0579e346a2ef65dece36fb0547f632ee5389
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:cc715214c0b86714a5073535b7ee394d2ab263698cf5eb5cc2f219d7c90868e0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:2d3ab2bf7df85ac392bcc98fce3d0ed86c785b7f1ec0db4a7dc3c121c0aeb5f9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:ce846ba8f74258740bdaf7ed324d3bea7c9ecf9e60ae747cb9e7508beb719120
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:6ec21444ae682e5dbf41cd22fc99652396a8f667871b9daf4770205dc911d86c