Sign inSign up
Node.js

dhi.io/node

Node.js 24.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

24-debian-sfw-dev, 24-debian13-sfw-dev, 24-sfw-dev, 24.21-debian-sfw-dev, 24.21-debian13-sfw-dev, 24.21-sfw-dev, 24.21.0-1-debian-sfw-dev, 24.21.0-1-debian13-sfw-dev, 24.21.0-1-sfw-dev, 24.21.0-debian-sfw-dev, 24.21.0-debian13-sfw-dev, 24.21.0-sfw-dev

Index digest:

sha256:86b672ec71ee614ae8dcfd24bf852585be258500750208136f73fc642ffa911f

Manifest digest:

sha256:7a1bd8f319bcbe6950f02bef7afb1b1120f918cce50b1998f1fd6b795d44b060

Size

115.73 MB

Last pushed

6 hours ago

Vulnerabilities

0
4
6
3
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:ce239caa276fea934898ad0e53299e9e7ddebf16664687695d48bb6b3bcb74b6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:803541aea017e196159a9e88c906e447b79113061dd64db21487640d8395498f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:80938b330e47ef9fd89a212b29bf8aa9a3cd7b89bccaf0f122763ea79ee4e38f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:69082961c8102f16bdab36d574fd3579387423939e94c9a82f67e1c49a5ac7f5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:1f5d417dd9dd206a24b3de9403eb9ca92f538adbb3ddbf95058e380b00b28c46
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:5869b052243ad8f960afa7ab7b918115771d5073b5367ea12d0653c5a08c2c0f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:f4269ad18c5708465cc9d9c4d09b50df8b5a07087911ae09e0032c8f601f8776
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:2f0928af45558e7bee54ca220a213f10e8ba556ce141d54726436fc47e97db47
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:152172c046b52cd64e148a63d0e32b39ce95af56d127cce447d56174e8725eb8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:f13147e3f28f458fc3c4c0b24723db927ea7c7a95b107ea1a35d0f409fb0064e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:9bea54afef0297e7584196718ef84e853d3c1ce76af918c68c8bea8378a2e1df
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:5989453e5a1f172dbe4dd96ac9c75975817816c724b502226ca89c99b6f531a1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:ec6af80acc508963c91bd442d4f0247ad8f813971bcedb2e8ce0e45dd57a71da
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:3305a37e38dccf07efd61cedbedaceab71887ac0c9ff3ad58888fa9e73748e8f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:d6e92bc8aa60810d3ca9a9590f6da604ca16c1ad5632aba65b92a3e1ee507313