Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
debian 13
Tags:

22-debian-sfw-ent-dev, 22-debian13-sfw-ent-dev, 22-sfw-ent-dev, 22.23-debian-sfw-ent-dev, 22.23-debian13-sfw-ent-dev, 22.23-sfw-ent-dev, 22.23.3-0-debian-sfw-ent-dev, 22.23.3-0-debian13-sfw-ent-dev, 22.23.3-0-sfw-ent-dev, 22.23.3-debian-sfw-ent-dev, 22.23.3-debian13-sfw-ent-dev, 22.23.3-sfw-ent-dev

Index digest:

sha256:2e2ff341601ad62b4038ccdf7aacb48f88f314310572748bab9b7bbed7032621

Manifest digest:

sha256:45d2981e658247d5cc838fe7fad2652daf624bd7fef9652b33ec7a5d9445cd94

Size

116.25 MB

Last pushed

4 days ago

Vulnerabilities

0
0
3
2
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:5753662cd6f3f8f573878b5301f7ff538e42036adc8afc3e98c0e79ad246a388
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:7e2cc4ebdbb39976df15b334dd25975dc728951313a01276755d01e468436f5d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:c08da04408ba667e671c534966cf01bd4c588844c56f05ef65b0e038ade9ed67
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:7ffc5bb7ffd8ee7b7c8036058de252a78df43eaf497f6eb34da4a684101394e5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:afd25501ea216ec098c3e23026446a391819f8ca5324d983f905388672e06edb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:e66ce93b03a9e5b0f7372a24e118e6f92c47b4b0a357e8e287e480fa877fe21f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:2425a248c5eb881b1d78e554adbc397077775db7eb50b5c449f226a12928ad7f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:fda0edb90c165f32063088fe16c17208f5bd58e3128c01ff88ffb04c897b900b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:e98bce30122dfb57174392f567233d983b06f18f645df33734c5ca8ae8297f94
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:1157effabfd07c144fee5bf0cc01c2ef5eeb4ccc5ab849c9b7eb5ca58bec9bd1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:30b8e37775ded1bb88bfeebdabba8c872a2d10b53fead983bfbf79c26c631149
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:d0066433857ff7364a101aa2dba4825cb4d6b3162e8dcc2fc20374b2c3f94a25
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:08f200912981d52ef5f1be895b44ae4f45f363742eb5407daa136ee7b3a769f4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:9e733223d247756762830ebefcbe51ada4f5d26dc0167eb7724de25c73930599
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:549da210515207dd2b71770af7e09222c06bfac5620b716d350173aef736d649