Sign inSign up
Node.js

dhi.io/node

Node.js 24.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

24-debian-sfw-dev, 24-debian13-sfw-dev, 24-sfw-dev, 24.21-debian-sfw-dev, 24.21-debian13-sfw-dev, 24.21-sfw-dev, 24.21.0-1-debian-sfw-dev, 24.21.0-1-debian13-sfw-dev, 24.21.0-1-sfw-dev, 24.21.0-debian-sfw-dev, 24.21.0-debian13-sfw-dev, 24.21.0-sfw-dev

Index digest:

sha256:5a7f739d940868615dc0c79ac93b76539e890e81c650966d7c552a72d0f3a458

Manifest digest:

sha256:ca1ecf8cc01300fa87125cc50a50f254badbf984904fe357d8a3857cef35e070

Size

115.73 MB

Last pushed

11 hours ago

Vulnerabilities

0
5
6
3
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:9f49796788d7beb3aa72cc86f99869d668b128e060eedfed88004d9386b0cb5f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:94c5fd6cc9e7d0d640bc748a7bfb1bcd2c5350d7d75a59bed69c44dbbfa6dbc6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:30201103e3238606decc6d11122381b07fcd25c61dfc8c3944e8e204358762bb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:c9025bd0216aee607d156321b06ec761b5b8842b12ddb7a1736c5a20313bf4e3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:2be9e0d5591b38a01422b918c6def9c5730ba580eb2020377399cf9f2478d954
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:1d49290b754a926e01e3e986c1e88fca0b46abc985692c2f1b6ba9787872587d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:d6993d7512e23d1a8c018c5c5c2664f64656216f1717ab9a00ad6b7ec8d2947d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:290f2b7ee01d532d6846a2171ea59e4e35ae7aab6282e84e00319fe7631eec51
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:cc56875f9f76e3241eed427ea0fb6fcdfdbbac92f70075428951b8e6f4d36845
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:e20a3b993ee124f326ec4db773b6149efb1d0771b0c70c56c0c5fd49f63cb29e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:58a552f9832a5199ad1ff2d1d5d221630a0119cb49915e1e5d9780826346f486
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:ef8b9c6093cf06cd07feaa131f51d47a38e61013a66928e9f3840ac926efb6d4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:67bd7825b0965825a91833a9eaf64e095039e92d024c2999c99b29c0d20ec091
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:4182e4f9df1d7d021779f001097d49aa1005400d68aa27977bed5bfe0508180f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:5393c537d0c1e878ee68889f625bae9dfcf558b543ffe7eddf73cc7b8ff5978a