Sign inSign up
ASP.NET Core

dhi.io/aspnetcore

ASP.NET Core 8.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

8-alpine3.23-fips, 8.0-alpine3.23-fips, 8.0.31-alpine3.23-fips

Index digest:

sha256:c9fdc60ed9b2db5a22075ad7b58180b687dae4f53120085ff8803b2a18105c2f

Manifest digest:

sha256:b5c1da524db5bc0b6376c43394e92fe1f345533c9992d3f14378f97d5f71ecfd

Size

52.27 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/aspnetcore:8-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/aspnetcore:8-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/aspnetcore@sha256:095d51e2e92238f3780babe4eabcf8a4619185fc47cd1e8f095c99d21fbef1bc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/aspnetcore@sha256:dff69ad531142b19fba7e494baf2c0488fb593b9b1ae2c552202de5b17e9a61f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/aspnetcore@sha256:52720a4eb9a541c7ab8c0df74581d10161b9be1dfdf9e845d86837da79b1853b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/aspnetcore@sha256:ca3ae21adb3869a6d74f74b2515bb10ee69e1b649b11783a3d2d9101942768c5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/aspnetcore@sha256:60c0962b691725c039c85f6f0999312035d61a3a0465452f9ba02e18460c6804
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/aspnetcore@sha256:bc26f148c77e2cf0b64c69295d48d74530365e9923424323be6f5bf1f7436e51
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/aspnetcore@sha256:ffd0f90089409a236148cb863d70fc5910eaef5c2433958ee3fc752864e347ee
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/aspnetcore@sha256:a98e9a76d2586e41a80ff05732a0dd4dc43171f4807e3b3783f14f86b8200dd1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/aspnetcore@sha256:354d11bdbb9da0833d31a39db854e7a572c17e53705fadfed4b0792db6c100e1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/aspnetcore@sha256:d675f0c5a7bc9c6b93bae316f906905241ea5437e0785da2145fb0be25abdec8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/aspnetcore@sha256:2c0ead3b4ff12e6f9f58773529847ca521c1803f86f0b9642d79c5e283a9af79
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/aspnetcore@sha256:a892867744b771cdc53e0883ad1cc9e46ccf75fe2af80bac4dfa3b6e3972b095
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/aspnetcore@sha256:935baa886b044ac575fb1b6e3581044143eef4b198d7906e7a88afb2eceb14f6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/aspnetcore@sha256:d1a917dceaa8fe2597743f924231e96c305d96d2bba0aa6bfe12abb67029565e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/aspnetcore@sha256:3fb111a59ab1a5c95e7ca58f5c4b4c7a24783f6608aea387abb15bb06aed8090
SPDX SBOMhttps://spdx.dev/Documentdhi.io/aspnetcore@sha256:da73259f87e0c603d93eaa97b8b1ccb7ff8ac88bd1284b1108081197269af0e4