Sign inSign up
Node.js

dhi.io/node

Node.js 24.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

24-debian-sfw-dev, 24-debian13-sfw-dev, 24-sfw-dev, 24.21-debian-sfw-dev, 24.21-debian13-sfw-dev, 24.21-sfw-dev, 24.21.0-1-debian-sfw-dev, 24.21.0-1-debian13-sfw-dev, 24.21.0-1-sfw-dev, 24.21.0-debian-sfw-dev, 24.21.0-debian13-sfw-dev, 24.21.0-sfw-dev

Index digest:

sha256:b098d411eb0c11287f195c2affe1247bac392650e51a9a3a6643ac4dfa56a6cb

Manifest digest:

sha256:5a38d098d2112f3c92372371967696e06b7bbaadd4bc326294270b6cacb91bc6

Size

115.77 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
3
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:199c523ab40fbd35f17986aa8d6a32fcc2c19da519ade8d62c4515017a87c8c7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:d9f0a0fc22bdb687352cb2cf7b864cc4476f580c246a5577104f19f457d3da4f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:590ac44f83bd496922719896118234a92e4a249bbc282bc5acfd5069fed2f389
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:6cd89a963c365a4daee94969542d2211b5f5347bfaadba91158fd9789a26662f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:8696061a07935a6c5bd24b201d0c0f530cf9f4f92d2bc0a444c8408480c1f9ed
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:8033ff6eee981d6ea0db1ddf772c388ff4d68e7b2bf45170a1055e7733077d33
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:c7cdcc82ce08e2ef0cc0af8a33dc2b5475fa15216fdd15ff9168416dccf7e15b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:00664dabfaaff5fe61d25978c3ee57ee6649a2692a5478d58e94def1c1688ffe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:61240e632cb19597188927d01e03a12d5728c51c3d60372123807a53061b62c0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:322e53ec8d6c8da421ec8fa8b10b0ec9e31a72a5f7c2e775fc983eb456272712
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:1192387f5a8033bb552ea97916a52101ba0a4f75f5561585bc50ac743eefabd1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:b7949320a3395443659ea58897a253c97c74b68e004772edb59a729b271b46a6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:5ba7b3b60423b1adbc41022f52260a6e64b60cb3d9b64553790703b9b21af3be
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:26dad562afe4d4d8ac9fedfbef062cd02da4940bda35bab56d6ab34eb0bc0b0c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:969ade02a3613850d8bd12ba6ec7979794070159786c40d5da9210055c1c4837