Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
debian 13
Tags:

22-debian-sfw-ent-dev, 22-debian13-sfw-ent-dev, 22-sfw-ent-dev, 22.23-debian-sfw-ent-dev, 22.23-debian13-sfw-ent-dev, 22.23-sfw-ent-dev, 22.23.2-0-debian-sfw-ent-dev, 22.23.2-0-debian13-sfw-ent-dev, 22.23.2-0-sfw-ent-dev, 22.23.2-debian-sfw-ent-dev, 22.23.2-debian13-sfw-ent-dev, 22.23.2-sfw-ent-dev

Index digest:

sha256:fab2753e553e56affb1f05e7cf72b12d20e7ca624665694923cd598955a936b9

Manifest digest:

sha256:64abb652f6ad3d12eeddb3a40f1ff2eb97ba0720eeea5d1ca0a1086d2e88de84

Size

116.30 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:132b12c5a58ce838ae67c30305e9a9bfb02fe1e4ad51c55bbbde0ae1325b8612
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:90434aa84de377d777056c2edd2edb2372a170a799fc14f706fab5ffc96ceda3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:a10f3145b76812a85921144b249fa00345d0e80688b267d340a039a172243e42
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:fd1f5a749af9afbc79da87b25718f75c21dc4c77e6836f59c9e39b7e85e7cc3f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:cff26c0b730d4d56937b39652ac430ed88b7f9a9448cfe08fd3496b0e052b0ae
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:dd7728a2126e4033aea3603008fd9b7a8c400a61990277fad47eab53e35fc1b1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:2f08698394c7c76c1fef8ac77fe314ba52a8e13ae93a1563336b4b48088de626
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:4dff458c547e5c6c8c12b1f36c102860e442bf7a82f2f6f4c6800f0b6a0ab572
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:9a84fa19e65a3c43ed92555f0c6d64c49c8a87c3d3a7fe81662cae8d898ab73b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:550fb420a657a2028bc597f331539e1342d957ec98ffdeca857e6d88598c9552
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:18c52cdbfd1a3740481ed02ab2da19bbb618609c8a3ede6386433ee7f1ce4763
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:c7e0a6ba92faea4937e0741cb2a493e8afe72f925d5234f841bc9b282319bcc2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:d0a85909c2796664d0aaad1d3d87c1bfc1f04a116c3f31f7a0b07ec39e9b0ccd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:b9728b9a98153b9f56d8732ee54044cfcc746ef49f39b1bb6d12e97e631ceb54
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:4a16abf08beb61776284629eb69c5b1495d70e50a09be6fcdc0ada0fe19d54cc