Sign inSign up
Node.js

dhi.io/node

Node.js 24.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

24-debian-fips, 24-debian13-fips, 24-fips, 24.21-debian-fips, 24.21-debian13-fips, 24.21-fips, 24.21.0-0-debian-fips, 24.21.0-0-debian13-fips, 24.21.0-0-fips, 24.21.0-debian-fips, 24.21.0-debian13-fips, 24.21.0-fips

Index digest:

sha256:27857d02abdd22a6be027567abd7138830a9dd1cd5e33be63ecbe9d629a4443b

Manifest digest:

sha256:a77cb7133dc5d976e8d5eb941d4cd18ff2ac8eb1c536a5983497bc9c0195045c

Size

41.80 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Apr 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:24-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:24-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:abdd25f187bdc4cecd1e5736a552da632043f08d0c8160e57525eca0a42e92ea
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:1d08c83524e269562933ef35fbf6fb00eb1bffd93a361ff8a77c5ba33358c188
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:01e7397fe8c121867409d6d9611e15a629a29bea6f8c0eef9558def49c61f44a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:32cb42ae01a287264029742803bbdbc238f07be7d1318d8b5bb9be6637c68072
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:711d42462bcbafdbe831936387078e30829da13b71f442a66cb5ad1c26341cc5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:813751d06eb704f172935fb7857f99c2cd01fa449d34c59b87393044e377560e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:5e62c51ac0470036044382713f45d629a951dc789b48ce3e49b837ab7e88a5d7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:e8506915cf13e9cdfe54d383f6f5b1f154cda66372951783b309aca9b31ad11e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:ed599aeba3d711a3ef63f3a5f49b9ae57520543bd828863a612c39b53dc8a2b0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:275898f4ba795bd7602fcd8eb928793e3965ce658b0e31117a0cfa6c35d66385
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:6cb62cc8c68966144e85615bcb32a74921909883792e1ce353eca7f23d8003d2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:0dcf9c5df9a55028a34708ed98e68b1ab1e955043b3004638b826e03455e831f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:54e7856e37a41d886a25c4b3f9aa90fdbfc66ec71d99570eb8cf5da812d9fe91
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:1ffe873891fc868dbbc0f7ed299ea493ac33c7c89c201cee970df9748a2220c0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:d041178ad506af54134f1fa377436969ffbe8ea4318210ab39d01795955f0c1d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:f3bf22b3c3162521bbe52651b6e7a1d26572ee7c2041b51f8d049a7bdf2bf1c8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:66116d6bf331ea10a5ea847bfff23e3cda676e333183dd60b99c3f5d707464ec