Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

9-alpine3.23-fips, 9.0-alpine3.23-fips, 9.0.20-alpine3.23-fips

Index digest:

sha256:53299e63df25098cc7d9cad3ad842fd977a2032b63e9fe171d8fd5588ea37f20

Manifest digest:

sha256:8ba87ef1d1e963833e33de815717d6eae893e4fc657e5424da7fd843a9855642

Size

44.63 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:d524f5e6c14623000e3e6c457d877a7bee3d5b3b9c658c397d31c90634fd2bef
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:467228824cd4f55ae0c728ed98cba16c88226415b6b73fc3192f175b390ca2f8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:a6b774eb16168580bc6222e44cb7c3de16a5ed79a21c67c3b30f8e559753620d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:aa7c1e0402b553b6125201f37202b7cb9cce5d0a085d540bd200aef18ad7fced
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:55e4c7aa797ed5ce5e4a1d7ee3d6226d073ab1f12d90c7533d2da19e64c09b2b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:0c3b0c0c892d35ba4d5bfc15e4e27298aa95ba679b6552cd31b611e1749921e1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:14ea8205b7df287239059866fbdb2e607a002c047f59f1d330c2bb71240af8fe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:5c023d6cc5120f4640fa91434bd5247fbf5ce4aaa048d3398194037c08d5e95a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:e7fd52d8f1e441d58a06ad4dde3a24b84ddfa554b5963126d2e74c364c928b90
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:3f8f0285d7c01d075bb776a1a759d1d494210a8fa75fc86d4a669bbf59d6188b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:4c9eb3d0fc095aa8a64058bcd53c7685998dd7d8f70bcb7a1e63d7423a481233
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:082b3973d0d5b554dbe47e730039976e450f740412ac437c15936a050cbf75d8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:422e869b3279bd5b7f59f1597a7c0bae35f80154b9e2bd8ed35c84d5f2fe8b3b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:3fe98409d70e72d05fbec43f8b80682e86900b205e2baf06080ea66158290173
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:fa54137740aea152c8e4c301389ddaa3b02e6e871995ed254d0a271174334465
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:6d7120acb11c3c9b7713cc49a586cafcf0f430c0327903810ce0a24c0791ced1