Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

9-alpine3.23-fips, 9.0-alpine3.23-fips, 9.0.20-alpine3.23-fips

Index digest:

sha256:34bd52cab19fe3b46305073a47b79f761315540fc41754c7dd3de83e23afa94f

Manifest digest:

sha256:1e0829f36f5a2d3a28a3ff0e2ec79da4f8e8299c225601daf2d5d97f9885d8c4

Size

44.64 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:6f101761daf5cee421214571371e8aaed543d2ff3d71236c8858feb6de033ec5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:ead451705c2919fb0578833dc94d510bc8e5dac94608fb53e74b8e546a15fa16
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:e17195fc731cf65154505fe6e4c4e6422f06f935d15a5f194243b37cd1f51382
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:eb8a746dc5b3f4864c806d8799f42fd7e2930d79506f404153e7342309fae448
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:f507bf93d7ac2708957d2b9fc61d9073afbdff1ae9909cc45da58561b3b39c5e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:61a7493c90e49f413503d8130e2647cc67924ec10f9e779a821d9f07f5411695
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:d9b3f2e65b95327c669d128517cd12e5a8097df1d26a8348eb0ea4262836c143
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:1f52216e6b5b07242015f8bd4e8320421d24084001ee04634538c68495fab56b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:fc3f33f435800e70df7f3bd676931e4a40cf8c27541ad1d8aca8a369a4ca7eb0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:48e6f2975cdc4be1ecd78f8473deadda09d05ee5f1725811f7052022c72dfe5d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:7b15e86d2362648340ee9f95a847d8ea8e0f2552a3bc88a72965146cb5b71155
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:b671c1bae61350117b071b20af9b21e1ee394af5d13317b51959a54d9c0ccbf5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:bb880e4446f62b9ab1195cd902931e2c9de9a347ac5b5ebfaee27cf32382ec07
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:df0d5700a5b65ebbf58d80ed882d3980995bdb8992ae2651ceea26cbf69e398f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:002255ab19fade06c51dc5b91dbdb448a8b5d50a654bcc63a19e86f7ac006b6a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:1a4306f709120f6ff807c8441d3b3c83fc58fc70e1f8fd2f07df968afe2b28e1