Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
debian 13
Tags:

22-debian-sfw-ent-dev, 22-debian13-sfw-ent-dev, 22-sfw-ent-dev, 22.23-debian-sfw-ent-dev, 22.23-debian13-sfw-ent-dev, 22.23-sfw-ent-dev, 22.23.3-0-debian-sfw-ent-dev, 22.23.3-0-debian13-sfw-ent-dev, 22.23.3-0-sfw-ent-dev, 22.23.3-debian-sfw-ent-dev, 22.23.3-debian13-sfw-ent-dev, 22.23.3-sfw-ent-dev

Index digest:

sha256:d52a51b5fbf189dfb94f2540c5d1c9c8dacf6af6e7606097240c8b1c502ef9ab

Manifest digest:

sha256:9e8cee8a721fc661df51fbfd995b8d9d7964061492e1ff641b9d050af2c52a07

Size

116.17 MB

Last pushed

1 day ago

Vulnerabilities

0
4
6
3
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:28e3ecc85a7ce27e9bf8428808bcd749534c5f6447665726e9277ab006065172
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:d558851675ff49b42c47d16a5c9f68d44251aeab25bab263fbb10d99e08dbddc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:52e5ff1e8795c795336ba48e3f8a9b598c64f1b865335edb6369c7bd93c06b40
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:ffc9ebec3a01c63c5ebda98acb74bc4858ee256ba5d8633a3ed18ea95ac22919
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:7dda0c9c6254544e87f8386f2b27cccf6bf9b73f52afc7c212ca04a6972f32c9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:6b3a6c3ef12e964120034b88cbb052450f90c8c96ada85e6e3c9a3ffc8d526d4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:8175bb3f01fdac28f9b8906bb04635eb24e64e96ed00f8beaed49ae99544fba6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:d74824eb5a1706fc55399081eae6f4c262a87ee95072a08a6b10fe4a1004e839
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:9401dc02fc8dcc532e56ba44f4e33dfee1cee0c10e1c39b6ba4e22e0549fe444
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:9428e7402a908bc4fccf02df15bfaec45f280cad08f454988bc247ddd171f33d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:48b11a364157b9066d70caea0d7be01c359fcedb5e56e6c59b199955f0c5039f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:968578db25c11d46502509cfe4fad30a88fb64a37c325911326d2edd30834d56
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:fb89d934bf0adf540973e91e3acfc905ad67635af9a9b6f47b7425fee08012d5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:8eceeb731cf0d406953ecae376a1afe1bcdadd832609f09839d4f3c212bc23af
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:0da3b24be253a22cbe078fe2a90328f8560f047a8f4dd236f3b8bd75b933c6fe