Sign inSign up
ASP.NET Core

dhi.io/aspnetcore

ASP.NET Core 10.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

10-alpine-fips, 10-alpine3.24-fips, 10.0-alpine-fips, 10.0-alpine3.24-fips, 10.0.12-alpine-fips, 10.0.12-alpine3.24-fips

Index digest:

sha256:bf1aba1fb767c5811adfb8ccbdd5becc10336e650dc2c78e3a71037157c79d73

Manifest digest:

sha256:c296448ea51a6e8c047ae46fa0568455203f9cbd3b83d02d6e486f0bbf0e963d

Size

54.97 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/aspnetcore:10-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/aspnetcore:10-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/aspnetcore@sha256:85fd7d7a82633ac18f35fe62496a316922a5b4c8f576b0f289934a609b4ad1da
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/aspnetcore@sha256:af2ef86e0e7ed9f8dfe09341ad52fd8057570b0ca7860d4f66d6d60ceaf91474
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/aspnetcore@sha256:c2fa97b903d10f4151b2e20296966ada667bed747e2b4180d42cbb9416c46ab5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/aspnetcore@sha256:7cb14cd297ca2d3af1e883551e26ee5e35bd83d72ebcc3c36160d9a268bcf819
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/aspnetcore@sha256:c560ca90c1b2d90587458c5b7e88c6f4ae5f413bb2942946e91a5acadbac6246
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/aspnetcore@sha256:78d6109f5ab7fc192da1fe689e902c64a81a43ed526d4739066f3706ed61ade6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/aspnetcore@sha256:d651733052a05c30cf81e3117cff70aca7c5ef2d27419a3fd62f8ae8412d0ebb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/aspnetcore@sha256:de4cf647795bb0b15d8cedd70047d34c9a27e526ee011444d4179911f069474e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/aspnetcore@sha256:0914c3b1edeb21de031c2c3e5411cdbff7e099880fce8ec7020a39f9bc1aacd3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/aspnetcore@sha256:c932f3b7d852c35b00cf34beca2639564ce6598c20fe411904a31290b95eecfe
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/aspnetcore@sha256:d0ca79efb0f110f4a253bc40a1c8077d22d894bf99fa16dd1555d5f1591a35a3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/aspnetcore@sha256:0eecdfe10193f3ca8e63b9b120fd29847dcb2f384740c157b592ca433ce98b6c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/aspnetcore@sha256:e48577bc8d8ebcb4d2d0311703511f9fc6450455cf187b8a1d1a5b76cac7e3b6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/aspnetcore@sha256:9bf9321674a74482551d9a0ccc77982cf372df06e7596e2e51c4e607f39dda88
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/aspnetcore@sha256:66bb17be3b3c19fa9039a7ed1624eaec5f24b17d3a77ff6984c26290574d6853
SPDX SBOMhttps://spdx.dev/Documentdhi.io/aspnetcore@sha256:29733584d2186bd403fff7c8187702cff1d79c5a8f06defe44f70e4b6aa80cef