Sign inSign up
Node.js

dhi.io/node

Node.js 22.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
debian 13
Tags:

22-debian-sfw-ent-dev, 22-debian13-sfw-ent-dev, 22-sfw-ent-dev, 22.23-debian-sfw-ent-dev, 22.23-debian13-sfw-ent-dev, 22.23-sfw-ent-dev, 22.23.3-0-debian-sfw-ent-dev, 22.23.3-0-debian13-sfw-ent-dev, 22.23.3-0-sfw-ent-dev, 22.23.3-debian-sfw-ent-dev, 22.23.3-debian13-sfw-ent-dev, 22.23.3-sfw-ent-dev

Index digest:

sha256:efc281ea01bacbc59e6b3ccad2fc6f3be12d7dda70c713172d0a6f3c224bf58f

Manifest digest:

sha256:c282da5c8aa9280fe938b090ecb8a5f3ed21f9000c363c68c314569e8139b266

Size

116.17 MB

Last pushed

20 hours ago

Vulnerabilities

0
4
6
3
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-debian-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-debian-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:0c07f3977c120253a3db0f7e29ab0592d32a5a6d561f2fe56a23b77259771f0e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:0c767b8a283fc4c1260548fa83ccc44f50bfde9bd7af2daaabf436902a2232df
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:dc192afebd3e22089ae1cf2650c115b29081709dfd1af9961e83f851df11fb98
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:9f63141d83f12d816097ec845f0b00fa1cbbcf06f52fc3213fdcd231cc4b5bb8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:115fb8e01b0f81d78fde3a507fb3dfbb9527728143a5b43dfa316eaa548e8961
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:8d7d8d73700043b6f87071e3b5247eaab9b42af5c7c16675fed2b2b67dfcb651
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:62a243dd0baf6528fc2ba12493c1cba7096d4c4d862c0262514b4229787573b9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:b875d063ef43c7395e6dcc76708f6ebad35f0ae6fa05913de843e31d6f549b5c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:526838de90871f8bc86c9308a69a9bb65c493f1fc8b2d901357bf5b970e175c5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:31c24f2fde7991b215aac21e19c7114feecfd04c535b5863dfe35a52128606e8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:6d6607803909622b3cf110e572aef3e39af8281011f0c3cab0886821cfbe2523
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:cbf4104a5639cd471f1eea0a21c8167afe4e72c0661ee3e6ab6bdadc52642ce8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:c6043918e14eae7dd3a6c90ecf7b4fbdc9c0db5406f2d568af9743a43dfe505c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:dc500ffa6d354e66674e71c7652d9d4efcbf749ec122cb2b5c30d194b2b367e8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:8f2d964c90ed0db01c867f4937e3c337b95759e784adddadc0b1649052a5d614