Sign inSign up
Node.js

dhi.io/node

Node.js 24.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
debian 13
Tags:

24-debian-sfw-ent-dev, 24-debian13-sfw-ent-dev, 24-sfw-ent-dev, 24.21-debian-sfw-ent-dev, 24.21-debian13-sfw-ent-dev, 24.21-sfw-ent-dev, 24.21.0-1-debian-sfw-ent-dev, 24.21.0-1-debian13-sfw-ent-dev, 24.21.0-1-sfw-ent-dev, 24.21.0-debian-sfw-ent-dev, 24.21.0-debian13-sfw-ent-dev, 24.21.0-sfw-ent-dev

Index digest:

sha256:9ea701dfcdb667a908e0309a656bf20c000ddaff8c5dff161ae00015d6c35ed9

Manifest digest:

sha256:53e13251e1308305e0723c7b71d2a8a05bbb737921dcbf642f5754eb452e1107

Size

116.42 MB

Last pushed

12 hours ago

Vulnerabilities

0
4
6
3
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:8f92a73883a6f1ad97d66016faea81fc24cc042b11f3e1ecd3c33fdc408105fc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:fbc9e0197af5f521b691787463f277d5ca6c123dbe9d8d7fb03f666f637372d6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:effd348d1d41f7ab26f288e16f56ad86c562b3f97851e258ec94641df873b28d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:85390763a88b0d5c5ef95c6516e8c9753384e9c59e183f0e1c947a30fc906c42
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:dc846ce6ed27cfc7b6d90f00cb0ca046f1123c5ea98c3467b74513a316052e33
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:3ed043b885cbf9c4f63150ba1b60f095107a3e63a80bd0c7571c09dfd8d9d78e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:694e5092d4eb45f4b4544fd9a2127818ba4b0bf2edee3567142b58622f5b9e7b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:d88358cc193d0ec00dec9c8230608f11b67352ce161f13ea8adc5cb8bd60bde0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:ad124c7848b74ef11b2ad7193b783921ec059f2337d82b8724a71255ceafb37a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:6e8798388e139cece200f7768325bfd06e5dd28a598b80a8b56608a1a333f7db
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:a450db323e933f092035a6fefce132325e939c9b5381f30508a6e4b39ac933f6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:eb5cb225273f752f499e4a8d922149e3a354816b25a8915d111daaca2a4f6d50
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:4bc44dae8b9105c43dfe730486367d6a0a8805bbc7ee5f00ec4579850dee77f6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:f98a78ac8f57b7099dddb2dee94d6ccdd0b031519619bf513d27b1a38b3827ea
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:dd59a36cba9a160f6c71339fe3995cafce1ad95f54ea2d38d15de510e4d00786