Sign inSign up
Node.js

dhi.io/node

Node.js 26.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

26-debian-fips-dev, 26-debian13-fips-dev, 26-fips-dev, 26.10-debian-fips-dev, 26.10-debian13-fips-dev, 26.10-fips-dev, 26.10.0-0-debian-fips-dev, 26.10.0-0-debian13-fips-dev, 26.10.0-0-fips-dev, 26.10.0-debian-fips-dev, 26.10.0-debian13-fips-dev, 26.10.0-fips-dev

Index digest:

sha256:e159bdfab8f6c987b3cf1a9e779599de4c663b314626159473742097ae9f323c

Manifest digest:

sha256:17dcbd277eda27994c436cf8fdff0fb58b03d64e098130e45bad17171ad91449

Size

83.28 MB

Last pushed

5 days ago

Vulnerabilities

0
0
3
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:f7d6448bd197da27106327c1bf20e7d0ca63ae60d627e0fc10ae0afe956a8eae
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:64b21bf7e7d4a6f451e0b2e1ad75d0b1f2c86e3954c354e8b0e65eaab5d2a303
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:2bcd3a9921447f3d4bc03fcbd34d59ca293de1532cbd844a3a56c62dff52e50d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:08e72bcd745013e4e17ad9e3c8d40dffb255f3470a9c77e49fd98e65d5df05d4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:eba697da0aec4d935377d82ad3d11a67b932a30a77ccf2eb069dc94d1f0dbd05
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:aecb8e67d9cceb32d0b188ee7c38615ad7bf651c3fed6be1a505309015bc09ca
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:563ba957791a12968793aeae7863dbac877ca76e7ffcf1d05b327f5db779687e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:6c0dd96acfad58e89922a0e04d3b9017d527724d1ff8ad9ef53db8103c81073f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:530694d2d45714042e341dd109cd34d8ad00f83929cd7287a635428b0f9861f7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:fb41005d60ea6a58d8d95aaf38b7ed6c3e91e3867e676c4a468d1962d5cee8de
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:38bb2cc56f82a4fb4ac42ebc103df3e1430d28942c6e826a916cf2891d30d6c6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:8f5691f6b8b0a0215eb47b3ae9bf4fe009874a0757ed39785b39cfc1b0482462
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:b95824c23197f931936e4e25190a84d87b9ab91b7eed74a6b5801a219973d35d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:3790d37f7a96c36adce4bd0c6069edd0cc94bb0bd58fca267766ca9fd6367898
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:e171371219e360f3ef9048ff94dd1c016d69e23b5b63994f2a0581c6f9a54039
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:c2ccd1633193373b0aae2eaf969c55f1a8b2c2f1657e9c947ef978be1e328249
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:03e19d731714b138514f92d94e06de2bcbd55c84cb564c150f3503913136d217