Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x SDK

CIS
linux/amd64
alpine 3.23
Tags:

10-sdk-alpine3.23, 10.0-sdk-alpine3.23, 10.0.110-sdk-alpine3.23

Index digest:

sha256:3e354cc5af4f636e767e25cfe4e6156ace121706b6b9a2fa9933e9fa6a76ec15

Manifest digest:

sha256:12cea4d741ba98456ee3f1663a6dd99513c2559e5e8c251a6e278d72bdf9a4cb

Size

218.92 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-sdk-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-sdk-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:cefd8438197938002837b7c84f06e185301f3d16c48d09ddd7c7d43d45e31b50
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:806254d1a08b3a56ab889c0fe1fc91a030f82a9313f6de45c8937495bd40a45c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:125d9f536fa2a7395ac2fed6bba3e8492330c52e739ec547ef37ee7dfa23377e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:654e2dc8c28557431484d89e14c87407be918dc3c3cbaf45030237fa280cc0ee
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:b051a480d1e4ba2e4830089e2b30bf19c533359d9ff492d62d976d17b4eaab8d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:55fd11e59b7cbc3b89ad475af9be73258875660045a55863175fca9f14350557
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:dfcfa1ef22075387b28bcbb8fdd85400b8e1bfff31986d2db62f2fbb8ad506bc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:6e1197e0908ef9709a4d03aeff6b5bd23020b5477c9f82ef217c510a7b828744
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:9759b3ee2f74009d74e1364c496f75190667205ed65b2a689b42d9b2d8a1a000
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:3d85079b30d23a71617a120aa1be51ddd9ada2312136359cd5f17274d61cda05
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:8bec0722adebb5f818092ab5baff26cf18f25d513e199d0d5e353d04934bcf57
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:cc09f641448533d67b29d4192b6ff2b055f2a8c3a2d03861063b463a83f754ee
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:8becae8a56a207eda54ddfc57f210bbd6098bd3ab3d15460506410c7874a8dad
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:ba52fa3439197680e32d421fde3ef102215f5da0a2fa1695fd45d68cb5ce878e