Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

22-debian-fips-dev, 22-debian13-fips-dev, 22-fips-dev, 22.23-debian-fips-dev, 22.23-debian13-fips-dev, 22.23-fips-dev, 22.23.3-0-debian-fips-dev, 22.23.3-0-debian13-fips-dev, 22.23.3-0-fips-dev, 22.23.3-debian-fips-dev, 22.23.3-debian13-fips-dev, 22.23.3-fips-dev

Index digest:

sha256:8646dd1cdbfef0c6651d0f248b451a26cb9f1305bbfc7ca60937a8116412cac4

Manifest digest:

sha256:cd527265b65ca993da50d8c1e42d543abcf1c9915c7888872a6575794c9158d2

Size

80.49 MB

Last pushed

8 hours ago

Vulnerabilities

0
4
6
4
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:6be57d672de8e5524f6d3e5669f767fc067ac29e47143d4702ba584dca1ee828
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:30dc01dab28d81abffe8c1b44bf17e093cb462ac30d1168487d1adfdb4427618
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:f062785b93b0cde19644a055984600c5044f5b0b7e4b94961e2b40c2bf973a8d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:510c074c11f940f13084d2e6b0d12979a57a80811bd34aa0d132365da106ba4d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:4d0583d9da93f06c1f4336865d4602b33a5e5f2ff14685ce1e0728db287f904d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:26bf6c29555cdc5af7fa05fcb5f64b76404098d5623a05fb2a0e910b0c75768c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:a22f4903d9ae1fcdcebeb911ba4bd6d6da4cfc404ea1d6c8adbbe3878f4ee580
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:c3a9607af6c8f44bbd3fd3ed4ac58668e629ae830306398b24aa338124cbc18d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:9df17d7e9b715ba0bac2dad360ee8f6dacd78f9be79f8b16159d8cacedc6e929
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:dbe4dd4da2d0b63783cc051dd1c1ec6cc713b4afc59bce9505be61478ae8a8f1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:2cd632bd340c95c04a0a5c9f72c8b2b6092bff519df20dd75580ce5aaf5a1f1e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:0ed8315619ba2c134a22842d39485ce51b2362028dab56d7cfec496557408fc3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:834e989ed0b2c2aa01a439813ea064301b86b380ad363e6817cda07de64e914a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:6c97580a9b5e0e0360a06f6a369f6668281e3782b89129bf9ae58deb883b6c18
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:efc9c58db4f600f275163db9307b048a49be048f4377779ef9dc21c6782b6cd9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:222c5a102fa7ca2ed2df2b9a152b379dd7f29e462de10d7f65282971a1a83603
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:dd330e381bff2647d738c6be729cd49c9c7090aec4a6aa869b371e3264e85490