Sign inSign up
Node.js

dhi.io/node

Node.js 26.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

26-debian-sfw-dev, 26-debian13-sfw-dev, 26-sfw-dev, 26.11-debian-sfw-dev, 26.11-debian13-sfw-dev, 26.11-sfw-dev, 26.11.0-0-debian-sfw-dev, 26.11.0-0-debian13-sfw-dev, 26.11.0-0-sfw-dev, 26.11.0-debian-sfw-dev, 26.11.0-debian13-sfw-dev, 26.11.0-sfw-dev

Index digest:

sha256:c90b79589d5d43c7b3bdda6f0cd4bcbd235e74a8ed2ac6faa38c2622e9be51a6

Manifest digest:

sha256:45546691cebc9d1321d351606110d76e05e4fa01f5280941331304bd02dbb46d

Size

118.41 MB

Last pushed

12 hours ago

Vulnerabilities

0
5
7
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:264c1fc60ef9d4be4247060527827eaedf277f2b301fff367fa7b737d4412808
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:aa30371a71ee671b614faa4dbc9d5ec2f54c75e4684a990bbcd00ec14f9d3db6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:96e71910045eb33ed262b650defff87448fd0fb4eae0a82330c8a748e9fdacfe
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:2a87e2a62d8d1c36e7594cccbab58726fda8950301909385ad6c61fa310a0372
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:6e907542aab1d8861a11e9764868e648a72bd55906b36c70bb25303b7b32ffe6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:e7ac8450b199822fdefc2fe20e1a92e6fbf8e865c0ad0455a97922d167e9f908
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:8f39b95229e016da952b56f40c52f44c29e2fde90d8e6fffe99d90b517306de6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:7436ea472f931b0eefcbd0e6da59a400e378abb1d458de3c416b171d1963f85e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:b0a7b523fce88ccfc91332a704cd66e86ba1d4c29ca6a559369efb40c56f13de
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:b6530ce8551caf3388458030d4d2b2002603785e1578234ea13bdd317272e2c9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:90e50b14e44c66808c19944140696bc7b659ae85214c687e6f6fc27caab7cc48
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:73064160935cacda763cc52e83ed6796dd82317ba321d80ac4984b9025cf6724
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:27733b67747b7763fb82e519cccbd0df21060f6b1fc3e13aa6767eca044df750
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:533a20ea5f2abfaa3a88df382c1e938c9b7bebbf7ee4c6a42bd78741cb508b13
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:03d997ba339fc691580b5b3f84ff61c9264a1f8e810d7416fcd8734e23404a8f