Sign inSign up
Node.js

dhi.io/node

Node.js 26.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

26-debian-fips-dev, 26-debian13-fips-dev, 26-fips-dev, 26.10-debian-fips-dev, 26.10-debian13-fips-dev, 26.10-fips-dev, 26.10.0-0-debian-fips-dev, 26.10.0-0-debian13-fips-dev, 26.10.0-0-fips-dev, 26.10.0-debian-fips-dev, 26.10.0-debian13-fips-dev, 26.10.0-fips-dev

Index digest:

sha256:9f6921555e1691811f2dc19432be0dc9842884fba8aadfeb77d9ba3ae744a1d4

Manifest digest:

sha256:6b0502594bc002aab6df03b683b24ae58aae1ac867cec5e229e82a577f5da87d

Size

83.29 MB

Last pushed

19 hours ago

Vulnerabilities

0
4
6
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:56a2f192834d8a510f18e75f546a28734fc4589cad97e442e8e376d87efd9797
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:49ab1789acf3865135a69661dad05785c6e3833586cd42bbba92723678542c91
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:d3e75efe8e13f59c0d99ff903b09b1ac024bd924cefa13b2652c55f030cc39ab
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:df8b70d799126a8f397957806793348c825e0e0ffa951984020ef7098a762b03
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:00611eeac2468c6870303e399bb7137d7c56eee912cde83d840d00cc8c13ef0e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:ac5caf66c7e13225d011260d6c561c86c826d0a4afca3adc9bfb18c95e4ddfaa
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:78f903651bbeebcae22a3c01c4c0d20270c0b91d35facb794eba2b625e7fd9ec
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:20d5502c2866493bbe90489374575b1124a8360480d2ab17806cbb05e68644ec
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:65f41939baae85d85ccda07111a765d2e68cffd32e65443a2f2dde1b6f377a9c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:616b94f5b4d5b9990ff7144e9480e32683ed64dddc2a01e7f850f98dbcc6a648
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:c741fcc1f6464b6820af272c8575b2ded1cc90231e5197b50e470b4eada6bac2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:4bcbba6365f7d045344dbed028261037ea69c5777d21d5e9e3b83ee0d0fb642b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:5cc205507ae26592d1bc4ff186bb80e932a494471878b1d035468a9f7aff56eb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:fb9f302ec280e50d548f93814bcc9732a15609615e6ca1af5de2d46fa0f6f941
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:f2c89104fc98ea692e109c056b422bbc633822ef2031488f9c76013aa89ccda7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:ad03b0d1d51544d1ad5a9d5df9ad1252a2543bc20c8c3c8be9ff20321144f8d8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:78e859e203565e392ac04259b718b9042c7c69bbd6cd7e0548fa80807e59e338