Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

8-alpine3.23-fips, 8.0-alpine3.23-fips, 8.0.31-alpine3.23-fips

Index digest:

sha256:78d274a2ece95ba2770c823c272b85b01a0d7add02cbe182321f25a40f812f5a

Manifest digest:

sha256:1bcd6fb5b77a1b7c80418544fc0430ce4a6a290a86d2fd61dd8cc620b88d8461

Size

43.15 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:54e61963f365de70bc2ccb7982d035a052426442033948a0cfeedd88e1441ba5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:d0eb1609d87c32034d3771bb258b158cbcd15965f9f168b1a97bcc27dd972e9a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:536367ba2d60e70825b3f0cdeadadb9c55cb7637308474001d8647e0bd6dbdd9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:ae927715a4b82487373fe68c7137f345e3e26fb010896b1abbe967d2573f1fa8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:3e4c63e711d450cce50a969981338355d1dc48c67483a32050a9b38aa1193c1f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:e532abdadaa416fd21a892f32d209faa991fe96822d8a085913298e531c50a7c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:b7efa85071ae3a40e555c8c329daca3dd4b9b2ccd370d52942814b64fe872d76
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:68f2a458335b0538132e19b96fe289702d9d861f9dc31eb5f0d975ac0afd7539
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:807fa3438e25b1f44df6acbc94f9ca440bcd102f2099a1faba112596e8249590
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:38fa95e7d7d06ffc7124ce80a615f78aa8740b50d646b72eee58408e313f6c84
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:4641f1141222013112ec0a8b8907b139a41be61b46fd11481ba80c967d47edac
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:06a6aef5e44685e0592bcad2feada623145db0e78a84b87e9947deb92d0806ec
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:c3a9374ad6e178094b2043c504e5886ac829795ae77f325c9e7d50b66f167a70
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:b1965a38764cea7cd5ea6d02eccdd7d6c8b66ece4fc16f8f9cc7225c38413a49
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:11442c422799cd5cd185f438c29664039d427f6d44bafa78da6ca4f605bd9823
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:3ab23eac5515790d9b774819d0d5c869a88b9ad9b367c15feea80545c34ff8b8