Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

22-debian-fips-dev, 22-debian13-fips-dev, 22-fips-dev, 22.23-debian-fips-dev, 22.23-debian13-fips-dev, 22.23-fips-dev, 22.23.3-0-debian-fips-dev, 22.23.3-0-debian13-fips-dev, 22.23.3-0-fips-dev, 22.23.3-debian-fips-dev, 22.23.3-debian13-fips-dev, 22.23.3-fips-dev

Index digest:

sha256:366ac316c9bc25f7ed4274d0ab60d6265cc0c24ad139325f30eb7792a2e880f0

Manifest digest:

sha256:cb925357fcdcf1aa4b63607127194b1916f359f58c489531e6e691e9141913c0

Size

80.49 MB

Last pushed

1 day ago

Vulnerabilities

0
4
7
3
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:4f2cb35e4b43fd8c0c5e9318e7219b6cceae3e7942f5d0fd62f03a79c0b595b6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:0bfb7ce49500156d0af0598dd858dc0b322009fc6149f5cbb0ab6f34b09f4501
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:24f04278525bfbd8fc91744ac108929e0a8365ecf70449fbf5e871f8adabb805
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:59bd540d3ce762929c74972a5bf95c4cea0e0d7da94eea9c3e8e28141cfbbca1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:bfa906f19c13da938429cf0d80c926a283e4eab01b7dd0ef454018def9e0c8d9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:7931dd789b114ca3fa42b8f03e108f60a84f14d3fc5366f3a6c958db257cab33
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:748e834d6bb5e81f4aa0171ff2b9fdbc7f50b7b8b06f0e6374f5918abd9cee33
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:bfa6870f5e3676109ec8757fd328bc4f87bcf59dc99cc4d17e4838e0f5849922
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:e92a0111cd532e97eb488f1d1756dd99287fc3bbc5c2e7f40d3a12eaf4063b0b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:ac21eb13690cc9350e134fc647d74d1be13e2f1be563c62a6da0c8dc9b08566d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:7b2f09bf7266aedde988ebcccdaaf719a42a95a0eb4dd2c817f226dddeda38d5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:84b9bb687f36cf8ec7a6b3654c60fa768b79f75687fbd027550fa0e95d890848
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:0a625a44f06198f740626f83e53cd47e9ae3acf3fee1ad7ad9c2dd8de909f905
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:6046c90541f3778a76e71748265495550348f72923bba774ea1019fec304e131
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:bce3deea1d4d886dc1fb6987a308de315cdd26c25d0bf1bee6f44fb1202af89a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:91f03b9d6ade1715157553c531ca3cd83c141113b47f2cea45ade5de0ba28a44