Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
debian 13
Tags:

22-debian-sfw-ent-dev, 22-debian13-sfw-ent-dev, 22-sfw-ent-dev, 22.23-debian-sfw-ent-dev, 22.23-debian13-sfw-ent-dev, 22.23-sfw-ent-dev, 22.23.3-0-debian-sfw-ent-dev, 22.23.3-0-debian13-sfw-ent-dev, 22.23.3-0-sfw-ent-dev, 22.23.3-debian-sfw-ent-dev, 22.23.3-debian13-sfw-ent-dev, 22.23.3-sfw-ent-dev

Index digest:

sha256:2925fb80288361199b6650283b2fe41f16ede8eed1aa988e5e9a68fe06247350

Manifest digest:

sha256:4134040dbca9d34f916b01252e42a0f3f570591eeb9f806f55630c14ddaafdbc

Size

116.25 MB

Last pushed

1 hour ago

Vulnerabilities

0
4
8
12
1

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:412b63dc6c5f85a149d0d4a948b8185c41c3e7c05da73c3a9d6fd9214de5b9b2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:21b9e9aa51508a516100e2b2b2d1b913ee6f7fd013933985a048e86415a892ee
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:a2a99eba4504f3fc5077f2a4451815edd5ccb440b583368fc451b70a9a79fe33
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:fa6ed34f28a9ea0fd24ff1f3062eecd347311d2f1f5d2701763145ecc56694db
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:b4707c2a3878cc8982fbcd517db344a91fec08808a57599be1c917b21eab1d99
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:15816bf8cfadd6b75463e9b0f130f5dc6ebb6e0a53dc82ac723dab8a510c8ff4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:1cb2abfb495c2b41d1a76df8ffb4a5b7b353d4d08386bd2b73dad2e43a332eec
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:d9396020dfc4c3811cd7e39c7537184b58b76be44579bca40e9a8b297671e451
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:c8c1501dbd7c4eb22850acf2650644b652b3558b48659646d94457a510b1c832
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:71466699b0d415ebd0d7f10ddbba8719bc702c36c1d42433c7a535ee143e6bb2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:736d713a8f1d6116744a4470c6e384ddb2b85954f18f724993ceec4c303311e0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:7174f42a034373b9de5ffaca3fdd954056190e30b1ab5e0aacfe2233fdc87449
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:73f9c0ed9a3f62e27d6056f938ffac1f03c89753ee91beff9385f0175a47dfda
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:1089878a82e469b7614b359eb0f08db785ae831dd4aed0fadfa6f69c9e9f6a17
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:dab0ee3873636d590edaec0287e1c0ef0a119d15c02885a1ba3f55133df16cc5