Sign inSign up
Node.js

dhi.io/node

Node.js 24.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
debian 13
Tags:

24-debian-sfw-ent-dev, 24-debian13-sfw-ent-dev, 24-sfw-ent-dev, 24.21-debian-sfw-ent-dev, 24.21-debian13-sfw-ent-dev, 24.21-sfw-ent-dev, 24.21.0-1-debian-sfw-ent-dev, 24.21.0-1-debian13-sfw-ent-dev, 24.21.0-1-sfw-ent-dev, 24.21.0-debian-sfw-ent-dev, 24.21.0-debian13-sfw-ent-dev, 24.21.0-sfw-ent-dev

Index digest:

sha256:b33ebfc475fc9bb3ad2deced36586b4ceacb6e43399b9e08421195188ba64632

Manifest digest:

sha256:2572de2ca985b266975e2892f11acc1dcb5d67b1fd0cf98e1a72c72c84ad4d9a

Size

116.43 MB

Last pushed

1 day ago

Vulnerabilities

0
4
6
3
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:e1a156dd1b2ca00468b04cd0db6b84d428b2441dfc1697f1cbff16c9a6e518af
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:6cdf6e05f98485af33ec2c1c3b91fa6a83fb3e85068de654e4a6714973cb8d32
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:cd6cbcd2b60566e6c06ec731fefcbc220c561049a0379b909d54c78066aaceb8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:eadf0b269a1b0028a14eabda0ad599a9e837908e8e7cfa93a55cc9107ace409d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:81bc7e094118e6b5c556c9259502b820aa456674fe91e2d20bf02d028780318a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:a88407257c85d0ad43c20338ede7086de4ec2a6e988f81a6af24bb806ac3b9d9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:222b58b28f8432eadec059ab2219022c859bcb1f5f84e70169484e795ad4befd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:228d10aa353d2e979299d01985a033dfe41bc9453e66f8276a3d51fe52c923ac
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:9dbe38f410c8f11e7bb0a178c969771d136746320da9445c6bd5a68b2ce1e4ec
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:306b313913cde2ef73d2498f5de8463a8b2651e081dcca2f02861e1834ba2d8b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:9d5c3c4eaed24842b174895829c4c321bc7e2194ce91c37e6f183d47c71d7c27
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:47c3d74b611fa488fbc4e03d918996718469c0cb12874eb9254cbd128e81ebdb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:d248653e9672fed993d11e0e35c90b3e46f831fb1a7fb99abe69c08d03fafe62
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:b308e3269a6b94e026c9d367106d6bbd310119f7d2928cea1a9683975ffd97ac
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:9266b33f90f28b0caf34b31f7ddfc6ecb4e1f43ccac9689b0eeb8cec1d6682ed