Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

8-alpine3.23-fips, 8.0-alpine3.23-fips, 8.0.31-alpine3.23-fips

Index digest:

sha256:171319f71ae3285b7917c1b47692cf145fd9b711892b9491a6649bce3d1eb544

Manifest digest:

sha256:6adc41256d97675e19510a390bc6caea9c1b8a025701cbb6117ddaeeeb0d55d6

Size

43.15 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:32d991b4454594b9bb6431af9049dcbe581029705ea7b03844f567c9fdbed4f1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:7006cc53652a66769f613ea71f2113380ee30a0095bfd521532bb36d9816d8b2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:5af0749997653262f6af7d482559e8fe5e3b82274b1ff822db1391ad80bf53eb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:b503f429b1d2548f95194b6e46a0f1ea5408ec4a0851d09dca73b7de2924d1c3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:ab11e07fc5e89261cca3048b77088e20c1eaec9326b809f85ff270e1dd3c90e1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:3db02180d60ddd5004da3ed52b3eddf0b7c9df9ef9ca5a8ff0576c92aaaeda92
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:18729d418f070ad7db01b6b29331f04ffe21d86fb5c40a7c1a09d56005b8c535
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:e67d73d9d9e2ca2b15d5d0678b745d06d642f9bbb98d4e9731699b8814f34df1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:56ceaed5bac58592e84d73a47cc63784a2c37930b74c47e062979e9af0561f60
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:e28e1a2ba9a8fe618c475f4bf3500ec4c7bbdccc48d1edf0482482bf850ca738
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:b821219ceb5fc383bfa4f29dcbbb7c4913da295d765dacb0a459881ddcc84015
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:43f4281d6b5642dd7548bd2865bc5c0e7593217252431ee958178fa959bc66c8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:3c7e875e8481f0aa34d503af69434a6b5544b1fa2195ab3a21021648cc622f41
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:9c45d3fc7c664258a0e783ebabe9c03cb520e4deae97fe175f357eb4737f40df
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:612b05a72942797f9e61e02aaa159b114e8767c54fd10f9e0d86eedd5638bacc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:db90af9076a018ac80d5287c504de091ececd17efaef6c536a4906702c6d2bf4