Sign inSign up
Node.js

dhi.io/node

Node.js 24.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

24-debian-sfw-dev, 24-debian13-sfw-dev, 24-sfw-dev, 24.21-debian-sfw-dev, 24.21-debian13-sfw-dev, 24.21-sfw-dev, 24.21.0-1-debian-sfw-dev, 24.21.0-1-debian13-sfw-dev, 24.21.0-1-sfw-dev, 24.21.0-debian-sfw-dev, 24.21.0-debian13-sfw-dev, 24.21.0-sfw-dev

Index digest:

sha256:84fb79344c48c0e701942ea91db91d890ea74a4922eff291d9df8e4aef1067cd

Manifest digest:

sha256:0c4e599446ac7af11718c94fcdbd74e932e517f3926aa628e49f00c75296273b

Size

115.74 MB

Last pushed

3 hours ago

Vulnerabilities

1
9
8
3
2

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:836ec03404dd789ca781e99a42d236150482eb771f2497273cf1cb7435e2391f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:9452f8165c8cff61718202ad882d90621b78b50b135b86b655d3af9716975cb2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:a4801986d9a571b4dba86de44c679fc18b4c0263e38046e04ff005ef28679a4f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:13f52c2e2713bed86a0091611f0ef78471ec46482ca97deb80bd0b00d9adc1e0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:0c5344e0ffb277264d347096291346414045da21a1dfb09d8f448cd7177b80c1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:e702d3001e1ac3894676e738c88fe59caf83b20e283c29b2e1b2c1ff9ec08d24
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:88c10d278a7d8ed6ca23f21ee5ed46bfaff46dfc424ed1c0f463fd28c206f69b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:8bb08c61ce5361263e5538d54caf74733a08f8ddaa3fe93316409f70425ecf5c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:e1b506e3aceffbb4cbc747db8559f764dee62712f2445ef746b20a9203473635
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:0f9d801028373ae5fdb64ecf3fcf4dc0095fd2d40688a89c8302f54751c69ab5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:b0e7f532b029791d4b6063b0f4fe8eed24f90894b9e4f2e299695aea431168cc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:83ef836669f6dc91814075c8308c5d1fb2b341fbcf6714740d1d6553d4f6b16c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:9845cd0cd7185454c0341d03fe967133bc0841162b3d9f97d80a296029fcbe7c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:37ccff359dd896ba54cfb6ed3d6d735bc9847e51d8e6fe97e524ec06811df626
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:125f3b0fb05e6980f7ac3a1ce1d2f8e4694b8efafa714158e7592e2afaaa7e8c