Sign inSign up
ASP.NET Core

dhi.io/aspnetcore

ASP.NET Core 8.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

8-alpine3.23-fips-dev, 8.0-alpine3.23-fips-dev, 8.0.31-alpine3.23-fips-dev

Index digest:

sha256:4c0b4420aaa810303da9176dbb01555071d3f48ff0feacf8fc1fddaae0b71003

Manifest digest:

sha256:8fd01e20ba388295334828bab4e2e90034b19f4406ee8c6d9851235304b4e29e

Size

56.53 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/aspnetcore:8-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/aspnetcore:8-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/aspnetcore@sha256:fbe3191992fa24a80065b15c21af8ab53d44acbfee72f8dd9dc2e3cc0fa6fd09
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/aspnetcore@sha256:5eec3cf78af5966334a5317d26e9cb3ebbd5b7be876a8625564a179b86162042
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/aspnetcore@sha256:f380bd0652bc9161109106ecbb4ee69a89bab3e7e9e22f2cca01b914341a6811
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/aspnetcore@sha256:b8dc4e1712198774746d761bcde32ed4308ca7929af650f239702cd67350ed15
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/aspnetcore@sha256:4ec24a8728974d4bc24fd8da522ba957fb0ec3cb322683a0d80c5757d06a6d7b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/aspnetcore@sha256:bbca99b82c629e9617a047582fd11da9fdb4a1e923d1bfd2a353f030e32f4bcd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/aspnetcore@sha256:2b953c5034fcb46e81ff0955554fc39a4d5a8fedeb789f56ae9b9569d1f766fe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/aspnetcore@sha256:f0c6f886ceec33b62cacc73af1395ecec3ec8b201109309306c33c21e8b0c032
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/aspnetcore@sha256:6d0205a413b0e9cf86901d30550e542415b8fd6927a432bf828a1e0c838f513e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/aspnetcore@sha256:80724b6b59967bfc7cfde21df652f68b7fa17263058cdb967920786f31e0d2dd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/aspnetcore@sha256:b4b790efb2dc5d8e78484880e925c62d4cbd4575a7304a887eeb47ebf87533de
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/aspnetcore@sha256:4a2c05360ecddeb189a6e0e00bca83c055dff1f4c71ccd75b47d3a590ef0e28e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/aspnetcore@sha256:acd7690b2d32bceb560da600306999ec747bb84173cbb82892b0fa08a3f68ff9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/aspnetcore@sha256:2257342ef5e99a42faac12c0bd34c3b98a0146a3a2cc5fd398ddd01e5098d17e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/aspnetcore@sha256:d2920b012cc70800b182789dab7b44b5eb47491493abd4be43936b46f0dd4a4b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/aspnetcore@sha256:dccb36f59960de20bbe23aa84384fcde00eff07d458cbd355f956e08c85508f8