Sign inSign up
ASP.NET Core

dhi.io/aspnetcore

ASP.NET Core 8.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

8-alpine3.23-fips-dev, 8.0-alpine3.23-fips-dev, 8.0.31-alpine3.23-fips-dev

Index digest:

sha256:953640c551451bc7ecd213eea1bed17f903ba39403603c7b382d8de2b1cd7668

Manifest digest:

sha256:e7c12ee34701d6f2e08ec366e062b7cd9909a87f6a5206130c9674b7926ddf93

Size

56.53 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/aspnetcore:8-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/aspnetcore:8-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/aspnetcore@sha256:66f671efa0cc9fff7b166f9b160942def03c7145b0667efe9fb27d9f908c5f77
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/aspnetcore@sha256:fa61c3878f77107560771a8a14d761119b67537cc2aae26c69ff49e4f0f4b726
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/aspnetcore@sha256:a96faa8559bd9dc9594a9cad305e62dd54c54d226dc3d92221b386d9932e0051
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/aspnetcore@sha256:8b1aa60bdf2e93a3d24f196586792304fe85f4ad4ff9b86bc85e3addf17aa961
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/aspnetcore@sha256:91d6e8f217d60a838ecfe45d7b432d2645bb96f0cf90acb47e5dc13df1c17d73
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/aspnetcore@sha256:ed35c63259bfc18bb087081afc9be21f2d97ae5c636463ef4aad8663479fbe80
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/aspnetcore@sha256:f149ed4bd0096fdca340675eccd668a5534e62b5312e03c00d1cf9b916826d05
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/aspnetcore@sha256:cf95b2ad8b2b7d712c78a4fb597be526d23cd56f4673541253f6aba1ccf946b4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/aspnetcore@sha256:56f63fef17152bdfe469977d8a4fef27a031f113fd799326228d940f9337bad6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/aspnetcore@sha256:86fa3d2a5562d9965a2b7ca9652e1fc508d9244ce6fb6d36eef2a96a7856a7c6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/aspnetcore@sha256:cf49ed183bb467490ac7e9a1f97d07c1dc7bb7136d671c4d154c055945766119
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/aspnetcore@sha256:c189bd13e5b578389710d72f8bb5d2863ed0190f91029f050be55dfa1faada80
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/aspnetcore@sha256:ec3c74810379d3062648e629947bbb702be7c7826d71d2a26e9cc3dd1e166180
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/aspnetcore@sha256:6ad05597e52b679499c2ff1c13ffe658f18c7471255318f5d141be33e3616b08
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/aspnetcore@sha256:e80a9d4149c891b3a18123ee387a41c183269a2a98e82e8e4f83b82e277e18b4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/aspnetcore@sha256:bdf1d3baed2137f115958721c0620435499bbdbbaf2bbb3989d1cf30facc4c6f