Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

10-alpine3.23-fips, 10.0-alpine3.23-fips, 10.0.10-alpine3.23-fips

Index digest:

sha256:d60e468e88363affd7a3abc85caf7be6c1b6a7c531c85617d44f0c8a8c0a80d5

Manifest digest:

sha256:972d2512fb87843529ce67e9493911f8635076030c0ebd6e35719410a7c89df0

Size

45.40 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:5a2a16a6d3137f08af101544f304e2c10b3c2b4f46bec69335fbc80353115d8c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:74514a5059a65d401d1d2c62b5fc731c5b1c70be36c4d00ad571b246715a0b97
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:5ea9895285adfa15203adda0baaaaa9355484147c8792e94ff76b950297e7401
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:2e3977e892c037b8b0ad78388753edb872bba9e39bbfe9b46c9daf4739c28a19
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:2493c51f5874d93b8860529effdf72acba59873280efa586e6f29f92d24e8a5b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:48001d98354db060ec27af2ce2551ae8cd37fcfb1fcc27bd30cf5cab78abfbe2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:cafb61ac0fc9b47d78fe2e46881f5587d711d9862bb3e7f96b411c4cb92e01a5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:52b32b4b91c86e6098ef1d36c2d7d3550093fd1e7592724fe1b2e513c5529591
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:aa7ac8c44cefc7726db6916f26f44b28c0e69efa49b0dbf46d844a433681fe0d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:137ae1a6d721f730a59aa4705bf298b9b5753ab3e5fa09aa9d7e1c74b6bb4aa5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:9fb5bb3184c45d6864bd852dc2a0317909955ba80ed755204f711bfbc6801e1b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:b174048dbd18aa9bf2a0eb5b60ab69b67d8f7b8cdbdadf89b7c7cd372768a493
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:39ee35b7c4fcaffd52c49848038e9ed49b9641b1d40d858ea0e34b6148425515
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:dd6641e71838049ba6fc1c3e57c4b083cd5f78585089f315c2ca20e57de9e5a3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:4245de531f63942e5cedd907bfe683eaa9fb83339c6bb5182a3e55fa6dadcb3e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:b1b684157032c533c9ccd78e483086c14d92bdb3fdb22bcb67f674f7bdbf41e7