Sign inSign up
Node.js

dhi.io/node

Node.js 26.x (dev)

CIS
linux/amd64
debian 13
Tags:

26-debian-dev, 26-debian13-dev, 26-dev, 26.11-debian-dev, 26.11-debian13-dev, 26.11-dev, 26.11.1-0-debian-dev, 26.11.1-0-debian13-dev, 26.11.1-0-dev, 26.11.1-debian-dev, 26.11.1-debian13-dev, 26.11.1-dev

Index digest:

sha256:67027a4f08a737750f5a6820968599c20b3d987cbc84ab826ebfbd7ae05c7f09

Manifest digest:

sha256:9457457d26fdba9e92d412c4600b33eea21dc83d0b449b6e18e89f120a7eb1f6

Size

82.57 MB

Last pushed

11 hours ago

Vulnerabilities

1
9
8
3
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:8df200af2d5425d7d3ab0826839bd181217c086f12c411273447540f687318be
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:f32eae19d1b565024ef5685e737e8cac8baaa338397b10afe0236543a0cef3c5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:15fc41f20595c8dd326b122b85c5c41730213aab726077d055e7fb20ca60d6e3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:270e021989cd8a0609e7dea049a605d01c259306ed02d134ef13aec7e47311c8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:057e7d5f7cd3bcd3c3ad2ef1e12ff628bebf152cdc23fd4d15f79b80576eb2c5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:35370f3a82fb7938342c20ed2dabc9af0147dc60ece69f79a424a418e28bc3f5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:39ae5dfcd793a0a2eb7442afa7f7b5fb8ecbb3ff61691b612496037eeb690bcd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:c5f28f71addfa6abd5c2f10de9506c2765fcacd4a69fb0832a49a31d1d81f98f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:9f4bd4f9620539f5e0fab7f9ebcf9e63faa7bfc9565ea94d01e54ee3c2c3fe2d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:05bacd785f00dc7c64ad4aa89d662d8541a58a1ca9fb71a8b9f93adb10188cb2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:9819b23745ee5c4f86c724742cd855b124759207eb9a8d4a623aa53459299c95
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:9f44200b1ef1521adf0a1d84a2329e77eba42f2fa85fbfd6a41fbbf8fb837032
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:6bdaff3164b6a7d337a73be2c92d1068228bf657be1f487d37efed6533edf608
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:09658ef495438d406523b9982785978b358e66aaa8951c49f88801f2f864a699
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:cbec316ded1e56aec8795db11fee846f0c25662cf167ba4e7f974c833142ae41