Sign inSign up
Node.js

dhi.io/node

Node.js 26.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
debian 13
Tags:

26-debian-sfw-ent-dev, 26-debian13-sfw-ent-dev, 26-sfw-ent-dev, 26.10-debian-sfw-ent-dev, 26.10-debian13-sfw-ent-dev, 26.10-sfw-ent-dev, 26.10.0-0-debian-sfw-ent-dev, 26.10.0-0-debian13-sfw-ent-dev, 26.10.0-0-sfw-ent-dev, 26.10.0-debian-sfw-ent-dev, 26.10.0-debian13-sfw-ent-dev, 26.10.0-sfw-ent-dev

Index digest:

sha256:0cbfb84469acdca29c89860d809d6d3028c5fd7bf03154814be8443ce708c78f

Manifest digest:

sha256:6e2959039baa52fb2248a412b129d25516f1001b9a21726cb276baec97e7dcd7

Size

118.99 MB

Last pushed

20 hours ago

Vulnerabilities

0
4
7
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-debian-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-debian-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:71fb9d3fecc4b85d27a260799ad87c61dee322557f9e2ea1e46501166f6b553d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:5ba9b296403e6e11b9c3cdbfa528f568bbcf0180eabd6a3d0574eb2108a62fbd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:5a1ef9d2c338bd754a335d44390398dc00ebd2aed205a37f35eb0c403d9c06f4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:23ac6a801d240af1e5b8325c3ac6e0927eed8c3e1e9dbaa894f13bda2df898ed
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:8c5f1b7b04f94723030a3ca32edfef0a60475a200adb1f6c2afa021a6e46c58e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:656a43787c36a9c36870f9d068e6a707a7814a86186fdb9bb6ae4b266b2ef411
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:a622d469a44e62a34fd86730a863f77194c4033ee88b03836c729db0d5941356
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:96ca1558132816de8ed1d3ee42850cbdf50a0a16bfeb0b392ae5d6e27dfd0139
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:57028d32c2269b761f74e8d9592112702611dd826d5432cee550b0658d2baaec
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:a686929acf4a60e99ed859bb1a7aedde38c24990c3d1dd6688ed09fe660a017f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:a3198b708d538d2c9bc273ae76ed69219727d4f877a0932c61f7daaea82d2431
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:207c90a7ddbb7679af06b5d9d92c2e6a9931cb812dd45a6d94f1ba9f5f44434b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:5e3f26801eb7ab70af96416e24de558747a4c49ae7480e39e81dd30b0cece9dc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:ba0a8d1e6a945f03ee492a422ab9c29008821d05cfac614d4b2209994d731cdc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:7634530b7d41424cbdef5d397b7d88f371f3d21c73fda6345db2a79dd434bd06