Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

10-alpine3.23-fips, 10.0-alpine3.23-fips, 10.0.10-alpine3.23-fips

Index digest:

sha256:f6c73b90b2ba5f58f25953a5793b5bf107f5cfceaa120056940b278fa7d2ae45

Manifest digest:

sha256:67660d767d4bb42cb94a1ccd14bf1a66590d921bed93f81c67f94fb3985168de

Size

45.40 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:f8b92a69173df506f4ea21e4e08dd29bc7869854e1ab116611f55cf047efb410
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:33c86a715ed097fef3a9ed57c28a2d448a1845363df437e5029a279c8650b86a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:a70f76f69310574d8017df2d903262df123c0f76c63c767f165af64dda3c9314
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:97e639a94bcc24b0beb373b2f91e4a32a58cc9fdc4f6bf4255d2054d69fd638d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:4f4e532be4731afef1bc44322e85c3f638cdbc9c4a87403b6f919cae6ac0d1cc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:0e6c5d95d0cc3592cd7fa6b75f59df5e60f01e39f88761c20a3326db0da5e6b7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:0c225f63958b12f18c7cccf7e2e894ca8518f1a4bb5af847589776b194cc8737
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:ae7bbe0fc3842c80f0d9aca695ac8849ed982f4fccb368d9d024423384694795
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:cd1090d2fccdb198769195dd1979da0f2e4889d4a725dad4dece7ac9fb438ae2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:755201b30ebc8fe56be89bff94dca7ffb92234c0e7fdbe0b0ea12021d07a61f7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:978719ef74ec7e2190ca2520ce28f63c30b9910b21dd0d8a01e3f7ae5a485241
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:dffcbd93f94675f36882f51d7901ea03c323b6237dfd4d185e8226456ea6b1e5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:7aaefb8ef65b926df4bb21df6bc4bb89e15a04fbf08149e63931dd68271da62f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:086b65c7947cc0e24821fd1909dd04830116bf3b96db8009d203c1143fb37711
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:b6a65a8631b91bdca337d7cf72de8800d7096503527af11c162a0a510722a1a1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:f5856014d8aafa62b14b3bac527dd46cf086ef7768d3639c39389a5710102ee0