Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
debian 13
Tags:

22-debian-sfw-ent-dev, 22-debian13-sfw-ent-dev, 22-sfw-ent-dev, 22.23-debian-sfw-ent-dev, 22.23-debian13-sfw-ent-dev, 22.23-sfw-ent-dev, 22.23.2-1-debian-sfw-ent-dev, 22.23.2-1-debian13-sfw-ent-dev, 22.23.2-1-sfw-ent-dev, 22.23.2-debian-sfw-ent-dev, 22.23.2-debian13-sfw-ent-dev, 22.23.2-sfw-ent-dev

Index digest:

sha256:95975690ef9c92c4621ca5ecce9bd317300e37b7b45ec076c1b7af57c8e40ef1

Manifest digest:

sha256:b39a658096887feb26b4748b3fd6b3c5e8c7858f7fb76421cb4056785c42c6b4

Size

116.30 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
2
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:a9c8b2cd6c4cabb6c7bca39bde7df5cb7940831e9ed46c44806360d97d4d93ac
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:218b20662fc80807b07899aec1cf38d315a54c34cfe781e2eda4b138ef67dc57
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:ab3fe0edbd2b00e9618119fb74cd0cc97033462032b6aa7e0a8d1931319027d3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:e6b9b529784b93826d7b19cf2db1f955d4413a34a91f6d2cd499b36d99f8e04d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:ad845c226a6bd1ccad3788cc0346b43457768dc6245f0d727bb546973ad5e85e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:5976236bcf38363740d2083a7ab12358dbfb533db681362636b06942730b6b8c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:779f25cd101e667310a83fdff674465ff6ad3819b0028b825ec4a5c10d48b643
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:840e344d21d3dd550a1bdd194c95f2d07009f6aa4acf3ca8a36bd7dc727ecea7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:fba82f07d24bd54954a7d2560f3dbf96c96843934c5154a9a2ef65a7f8c26d51
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:1d07c5f98da22568ded6182fb69d8086dfdbd194fe1ea1e6c90ba67ffde3dd38
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:1550fd2cbff4611e2a54ea83573e6db6d48f1e2d270d06817f2b58eb26c7002c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:bbcb73cf4b431f748e44b95cd78d262b925454424fb2488cecf830ca0a6e6f86
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:9410443926b40843e6bd377713a5849a3b28045a82ea26c8ef4c5e4e7e6de429
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:a1059859491c11bcfded848e57db3ee011a080c4f98441039501431535f4dd62
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:40115683a4d09073ee91b14c5eca9fc561698eb38fa6975e89fba348bf8c79e4