Sign inSign up
ASP.NET Core

dhi.io/aspnetcore

ASP.NET Core 9.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

9-alpine-fips, 9-alpine3.24-fips, 9.0-alpine-fips, 9.0-alpine3.24-fips, 9.0.18-alpine-fips, 9.0.18-alpine3.24-fips

Index digest:

sha256:084e526a735715271bb25d75f3935b84c2f38825f8b933c3f839d60002be3a9f

Manifest digest:

sha256:fe73c9232c94e505199dce0d800c0da26ab705e39246ed2aec46384e6906a046

Size

53.91 MB

Last pushed

14 days ago

Vulnerabilities

0
11
5
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/aspnetcore:9-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/aspnetcore:9-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/aspnetcore@sha256:799a0a1bf25c4d3879be837829d244eb76cf3d51bb3d4917e3035d9cb4c37e15
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/aspnetcore@sha256:6978ae2817c07624ed6a5c3ea0f96fe7ac941cd23739e6918eb6a27e517b8322
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/aspnetcore@sha256:ea8f5f8c2f5a62889303c72a147b8b5846b0b8e3aa88fd520feec437835b7241
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/aspnetcore@sha256:3839ce7cca63688dbe0ceccbefe5ee3e890447b76d065d543f4a52f502903456
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/aspnetcore@sha256:858a4097978f55dce7164a731f16cf90a8c35e2c0b5aad7e481f555942e2d809
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/aspnetcore@sha256:66e667502d282b360702ba57bdcb0eb7c55a0e321d75e0d68ee8598b658a1ddd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/aspnetcore@sha256:03cba3ee4e3d747519e596c539bd9dac952714d83e1e67b4aee947e51587c5a7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/aspnetcore@sha256:b64abd68828b0e42918bb5bf03d54160ea1d590698cea170173ee0b8fa4dcd16
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/aspnetcore@sha256:a6967ac908314a93fabaf0fc416e8b81e78c7e36a43eac8718be0e1ea15043fe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/aspnetcore@sha256:14ac7e5b88f43399b26281c8af9e78492e9e784f848e9b6f77179af400f98f0f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/aspnetcore@sha256:9f98ee32c13330a92d6a03a1f5c3a0948c4172d21f80a8dde04b72982abbf0f8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/aspnetcore@sha256:79ddba1c3bcbff8e9e724055c1998c771b00d836731e234ef4f105d9da452df2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/aspnetcore@sha256:b616ee49971e0cb72e94305a6226d13813f8be2142da686e9d2a6de027493a16
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/aspnetcore@sha256:77d8a2b3e76fe523b8aa8ba61fcd4e2095bd6e82362a29453cd2bcff58bd2960
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/aspnetcore@sha256:1a2ddedb3b4d5b77e427c0e10b606babdd7d06ee3d56b675a870f9bdb5808343
SPDX SBOMhttps://spdx.dev/Documentdhi.io/aspnetcore@sha256:204bdb8c60351e31dead0a1fe6c812f34c999df5f5d0f336672db6f1e9616b33