Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

22-debian-fips-dev, 22-debian13-fips-dev, 22-fips-dev, 22.23-debian-fips-dev, 22.23-debian13-fips-dev, 22.23-fips-dev, 22.23.2-0-debian-fips-dev, 22.23.2-0-debian13-fips-dev, 22.23.2-0-fips-dev, 22.23.2-debian-fips-dev, 22.23.2-debian13-fips-dev, 22.23.2-fips-dev

Index digest:

sha256:2837b1e2285d06c350bc462fe0b38899a7ed366e49472b95184b510ee9c5293a

Manifest digest:

sha256:31685cab61ed14a00b4e32a06982eeb5ac57487109f8dee2750d7938686129ec

Size

80.47 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
3
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:99cb4486447e787c49f1bd62fac01370fb87a8ea4c22783caf140bd1cc13985c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:36a8fd919abe988dec31bf34b44901d7b9f1ba360cce07f7d8ff94edb25ca7b4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:9889055d607d4d24b674b292c5365030d33ca78144343ef6baa3d0f6c6a6f4f0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:f5a6864a311ced5f691ee8ef25568f5f5895d61bb67e57bb3e7a5ed09ba8de27
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:4e89a46b29ed67eaa92fb85d4cc56992a26d62faf06be2207bcfdf14b2d245ff
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:e8b88f4776f83fe68d2866bf31c846f1d1f0649ef61f5984fc40f72a199a063e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:fe35ee16d1fa86698ff59ab1fa7b6f11176393227317e0cc60763d3318ae3f3d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:f7a38ffab77e6ad9d29f4c764bb9ea074d5c0212879602e0761a8108e2d7ce7f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:647592a1c32718bbb2ae26089f61c6cfd6da20260d3a6f09bb3e2adceb1c1a32
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:cf99ed4848670a6b9f7090160c1aa35e78c8694fe6c1c7c60d66e1e7f604fcc1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:102f23972bff5f60eb661a5b8174bb1e020ace52d4dd0eeedd307c2e4d124d86
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:5cbdf20e6b76c63e90c3ee2520fbf1b07def42db8720d3c11b4c3873722f2271
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:3894b89df8ac54e22be86aa2a3f93f7cd9d1d17c88ad0b4b93710a156afa7ce6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:96750862a7b9ade6fa572d53722b6b5a9d162afda821298ffb39d83985087a23
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:7d56aa3c5878f9716d2b5176e0ba2a0313e789f0d7240c8d890ee8f81f137b77
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:a7ffecafd698b9e57048b19f846445f52946131a86537a894d24916ed8c1935e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:1b7dca74877bf69e0451c8d1e0fa1678295fe00520762ee1008644c6423fbd60