Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x SDK

CIS
linux/amd64
alpine 3.23
Tags:

10-sdk-alpine3.23, 10.0-sdk-alpine3.23, 10.0.110-sdk-alpine3.23

Index digest:

sha256:458355960cf2a88ef3b5fac6d314519a4590df270ae062f952e5a5df4325b39f

Manifest digest:

sha256:4786e599d63fa6fd42e16b582ee9d417228a2442fb3ac2f17aff9d4df8afdef3

Size

218.95 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-sdk-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-sdk-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:f7f94a355c319bf4ccc073943520479ee6392b9add5b83e79cb6a57a924bf82f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:afb72408f728f1eb7b0aa8356e61de7e1651e9867b8aa61021dc99e936f6de68
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:16b62e5598629de0429ffa54bd60ae1e0605bf20e73a3109f7f3fdc6ad442b77
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:d8836d9641bb1e02cd3e191318ddb94ead7bfd060026b189adfda635b0029930
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:661e445d2ddedd5582c2b74f20add68f90db855a9143d80433fa30943d2f3f68
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:78af80ca0ac86341ccd135d3b8da255c92a1e23f31671b3846cd007f8926998e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:89fec1120cd1f4c945e09ea5c237cd21936917e5d75862c9ad9bfd9dc19930a4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:61f17cfd0d3084212591d0884ad35340fc338353e39d89bf0c23e1537bfe5ac0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:53c6bdcf60c75dde3d1c4230b5a0489e93da5eb6ab3d9ed1a2b8985b8330e9cb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:9c273ff1a6dc89a4724d71baa2cc0cfdbb006ae4c92ea77d50ece32a6400c2e8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:d4e6b099168e157ff9a86bce9efcf2914c1d36055873ac156a71f35c4b3f7244
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:97fbdc4f065553b06a77888ef81ccb1ae74dbac287ef028d4a2952a8abf87fea
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:2f072bfb3131ff3d5e72f829185274221cdc3e00160bac5ae893ca94009587cb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:f3844bd30e88c2f41a72dc0e885dd0acb0d39f59ca3d7af41b682260820e4d8f