Sign inSign up
Node.js

dhi.io/node

Node.js 26.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
debian 13
Tags:

26-debian-sfw-ent-dev, 26-debian13-sfw-ent-dev, 26-sfw-ent-dev, 26.11-debian-sfw-ent-dev, 26.11-debian13-sfw-ent-dev, 26.11-sfw-ent-dev, 26.11.1-0-debian-sfw-ent-dev, 26.11.1-0-debian13-sfw-ent-dev, 26.11.1-0-sfw-ent-dev, 26.11.1-debian-sfw-ent-dev, 26.11.1-debian13-sfw-ent-dev, 26.11.1-sfw-ent-dev

Index digest:

sha256:970a80a1e5892cdbe060f0dd622d03b3bd90cda892f6167fe406c6a57f40bea8

Manifest digest:

sha256:51be8386ad7fbc5f77b7252f3904402745b193cd6ca63fd4a074d7d3723cd3f8

Size

119.11 MB

Last pushed

15 hours ago

Vulnerabilities

2
8
7
3
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-debian-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-debian-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:27de31f261207feafed1229af44bc0cb468551eac50fbaf12d33e7685c87e6b4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:6ca0065b693fc298cbbfd9c83ceca8d34a6dec1197704d98110ac24b279652df
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:2902c0d5e30d2b6ec225bb89af5c8acd6e484a5a58e3f82ff17d16e2e5f48bbf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:cf8fe5501e825c17bcd451c266bcb86326d0dedfd3d601b51fdf5b5523ff4b24
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:42f61497b63ee9dede65ab96f03eecfb809dced5b3f537f5010b4f97562ef3c7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:d484cdde74b82eb0c4d0c222c8f728480168b40605b018431272e70744d734f6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:fa9c0cdc1fcf225d52221325a2b7ea9d9cae274e7d1008de24513caa3a5903ed
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:13887b2252532f2673848fdd676ad2574edd762ce277d4c1ef4210cdbba3d700
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:4b1887916a173d05b64f117cc1a89d84550c48b3e665fecb28d8207eeae6e649
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:7f2357328927b61b34c461d8f685e02c51fde03315a36d21923375b86b4847ea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:2bc261fc2c6b277efcef7f7c2e76d163baa46d3395d9ab5f1c6929938a3730ae
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:dac301023df83c4565e0de0d3a09b528a6b12242aede6f667551711670158bf4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:a832a946adaae0a695a74087153c8a32fc3f4072c2efa458f74b0c5c55305ebf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:31b6af06c55eaad4407f8002630b9819516795198763efc2c3f58bed3be105ca
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:12f848a7f23d0d9613ec7813503a0bb4fc7b9888d4e012fa41bc9d669bf7bce9