Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (dev)

CIS
linux/amd64
debian 13
Tags:

22-debian-dev, 22-debian13-dev, 22-dev, 22.23-debian-dev, 22.23-debian13-dev, 22.23-dev, 22.23.2-1-debian-dev, 22.23.2-1-debian13-dev, 22.23.2-1-dev, 22.23.2-debian-dev, 22.23.2-debian13-dev, 22.23.2-dev

Index digest:

sha256:178fd7e345531aa16db11c80b087b8ea566cd01bd7c226444736e2d23608c56e

Manifest digest:

sha256:7dee5b3d63ca4dcaa7266eb0bf3dddc5c85ab2b8e623a0e89bcff7f7ba82a947

Size

79.67 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:67f56df8b7954326a1a54e517e1cccaa8f05891890a02635606ed6c9e8b208bc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:25dc34abec6484ea51b81cb0bc0e1be668d368e5eb488abb7b9e52ac7eea3b41
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:e5efe64cb7114c363eaf7a5be0d3ea0cda59d7ce44849a139192ca72eb4c8a48
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:29ff4defee86a0d1745aa6eff6552bcc0ddcf84b43254d406e5a16f07ed642f3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:aeb09643279ea5b99dd604d24253884d18fb55c87d97f3b67e65abdf2a25e8ce
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:ef73f2cf6e50ad612198354badf9037a760a6cb4271788c20b9237d98ba2e7cb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:269ae7f64d44ba52cadf13d105179ca49efbdcd71953e425346f1b420838dd35
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:a50d7cd0f98a5f169eb9e307e8aad5cdeddd41e472e2c8b38458f0b532f099cc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:45bfd41a891c45535fc051427d17856761d850963641fc198fd33bfc088c9e8a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:fb6941cc41e59fe1a324f9db96e6ae97c8eda02b95c32229193d7c7b9d7fa9b1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:98b0b681b62ad8732f1c9af210b5dbdaf3f34505574d1368feae6fcb3c70b0d5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:a4ddb99918aab830992d5ae795a521517240f179a39c0d4b0945a8089416abc5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:72e1edf6def3338dcefdd9a2ad968d56e41ca4d6d69124763b64698a8ebd0f1f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:dab809e86b636c05e907d92e1290242fa80bc72030967e923d198b3acee2f985
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:abd4ad24c8c0d741d31079c47ded3111b9e00d058140d20f7935a82792dc8b3d