Sign inSign up
Node.js

dhi.io/node

Node.js 24.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

24-debian-sfw-dev, 24-debian13-sfw-dev, 24-sfw-dev, 24.21-debian-sfw-dev, 24.21-debian13-sfw-dev, 24.21-sfw-dev, 24.21.0-1-debian-sfw-dev, 24.21.0-1-debian13-sfw-dev, 24.21.0-1-sfw-dev, 24.21.0-debian-sfw-dev, 24.21.0-debian13-sfw-dev, 24.21.0-sfw-dev

Index digest:

sha256:ce24c0851ba108a45902ce7c52405d0be8e8068f6daf8f26900a503d2449ccc6

Manifest digest:

sha256:0a248640a58b39035011192f5d8b4af50c4982fe142c4af419460243d6ae3f26

Size

115.73 MB

Last pushed

16 hours ago

Vulnerabilities

0
4
7
3
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:800ce69a1eef786e83f513b65ab6fe5420e9fa611c9e4cd5c154ad16c60201b6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:ae8a840114778857168dd2aca1bce6f49ec5a42715982ee3c53416b6f3d68278
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:d22f7a5a9bd3d3ff6f1afab3aba40be7e3cfdde3b66d325583724f84efc56012
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:daa5bec0341357091be608c0acb24184e66723b9d6e5ac094cef5804a62bd1d4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:06b4ef49fb7edacf54e29e021f0898d88c775c1df6cf11658b36f073efed144f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:c257f6345951948bb6a53874d34f85ab236e5e7f354adf6b637281c548292e48
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:b51b33cab7c55f976286d420a5b5a353d55db17f322569235beab8a3edfb81ca
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:68ebd8f6baf8079fc06779ae11e7f174a3b2dbdea18d22b657006779c25d5451
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:aedf409984e2b05087f6ee33ce015433602b1eb9c91073b20179df8869d3cbb2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:3c68cbecf53545f3f0b2a47f50596f58a17a987d53ea71354d5d428766780d77
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:cdf77effff9e86a589023b5679c5a033bd14b2ab366beeebb3de10cd99dddc28
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:af76d0359fbcedaca416039e4432336d1ff774d4069f957d8850bfae2d58270d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:5191a651cc4cd57977e4db3bc66923af905b6f3104d1f3098603bee21d6179dc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:63eb560495fdd4bd0b772d5488c6291bf2f500f60edd996c2a8b843396f85bc7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:6f54093534cdb1a6b4e22f6635cf9626a01a25b408a43e868c0203fb45ade592