Sign inSign up
Node.js

dhi.io/node

Node.js 24.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

24-debian-sfw-dev, 24-debian13-sfw-dev, 24-sfw-dev, 24.21-debian-sfw-dev, 24.21-debian13-sfw-dev, 24.21-sfw-dev, 24.21.0-1-debian-sfw-dev, 24.21.0-1-debian13-sfw-dev, 24.21.0-1-sfw-dev, 24.21.0-debian-sfw-dev, 24.21.0-debian13-sfw-dev, 24.21.0-sfw-dev

Index digest:

sha256:40f5bdcfb6a6d22993fb2a58f8cd407f67d7192d9b08afec7a2c725c021b6a36

Manifest digest:

sha256:fc0452dd2d3726d5822312e9f12c5b8eb1d6c04b76e38f4f79f8447927e62ded

Size

115.77 MB

Last pushed

14 hours ago

Vulnerabilities

0
4
8
12
1

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:4a656881a875fe884bcce8c3decc47cca2a28df9d9e6a75e18ba6a9100ddb66b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:719acd7ced7e239f7c7d848af4b870e4b9a342d58d5bf6b452ebb82ebf453f5b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:cf1c2ec527c0bb45fa6f4c7fff635ab4fb01d4a9cb40471c809acd0cab72d90a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:3b256792334570f63e13d72200f5fe64bc59f37b0e6bbb74b760924ca0c0555d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:d3c55c269000974140247d9a8079b5a92d7d5b0ed6b99ade3186ca18d90bc06c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:79bf684cce7377adccb8533246cc1b167f0d18cb50c3fe50d287db15d0231060
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:e3bc21e560adacbab582889adb8062413cffbc3e41195dbd15785c87cd169127
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:39db9d508cda3071ed165407a35dac19c7e96ace76e20de90af0cbd71c5e5e89
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:9d5f8124cd52dd8f3c1f2dac85c6a25c1aed7b11694d72cff119c4fb81ffeaa4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:b1bd920dbaa69b7df2a43ddacdd34a7d5ce30cbf1784db33e2032ca57abc21ad
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:15872c429bf9418ced4d5499a2b7d968f4cae008467d2ae7f5562480b180aac3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:46bd66638e178d77c37d70387d1e91b49d46555f44bbc2ce82890c57bb133f18
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:9c481ee1b487845a35e261b7a67e26c1ae75fb2a34b9b2a74226d5945ecb6157
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:728361b8032adc31646071141af14e5b1a51ad9f890d0509c3c42fc369105cdf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:398c6c04cfac72980b6d40f819814f3538c3ac14bb2928a350c3b24002038560