Sign inSign up
Node.js

dhi.io/node

Node.js 24.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

24-debian-sfw-dev, 24-debian13-sfw-dev, 24-sfw-dev, 24.21-debian-sfw-dev, 24.21-debian13-sfw-dev, 24.21-sfw-dev, 24.21.0-1-debian-sfw-dev, 24.21.0-1-debian13-sfw-dev, 24.21.0-1-sfw-dev, 24.21.0-debian-sfw-dev, 24.21.0-debian13-sfw-dev, 24.21.0-sfw-dev

Index digest:

sha256:70cfb88dd1c56976e6a266cb250365b69509148b8414f96e1b6e731862810a41

Manifest digest:

sha256:bfadf0db1519af13a89e9b1881e39f9b629630bfcb5aa50bbfac8819be6c512e

Size

115.76 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
2
1

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:080e53b06be44a89b2b507cd3ca00d959f645b613a54b85dc810c04a6c8853ea
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:566846c67438af234f000d16462a8d7977ab7aef0d1ec95f5ab375a530c1ad8f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:c2d2fec0e10430b583ba0c9e32b3b12419eb84501ca07f1b4b5f765916a44231
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:9dd884c7b179ab0d134136d21727ad08bd85f145e349edf43e272378e8d1c8d7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:30f68ec6e671f6c2d4bd19ccbb7ff57e2d5eedecd97b123c917275896d57f3d4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:9a45fd2f50fb370dcad0b97857805db0d87b6de5d67d0a324ecc622161b00ebe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:522f35813cc1eeef2c5361b9e1cecf3da2688f6070e52196495d31db48130afa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:b4cef30923da138a45769c097b256e6507a6fbbc4a7187636cce5921c910054f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:d7676fe55b94f70772a30dd38f1e09273771dcbd78c123a32d2f1df46a5f4fda
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:ffa2e58da998ed6bdb643a7dd0d9991e646073722709e689b4ea7d799e1acdd6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:46614b0c6f43d6f8576825f08ec863b024c1508f24bc28b7fcfbea33869c3e5b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:9630977bedaf192b0a33736c3d2530b10d7c030cfbdd0ec67f7db987ffe94bd1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:7ffa23ddd5ec2caa83470193921dfedba990289c0ecb9f7380805cdee56dbc81
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:7cbdaff8329c135863cc1f51b0aa9bfc5efc3b0e2b4fb807971e8100e8a39f96
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:b256e3eea88b9fd18db302b3842ca83731916ed5172cd786956a4f905d686cd2