Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

9-alpine3.23-fips, 9.0-alpine3.23-fips, 9.0.20-alpine3.23-fips

Index digest:

sha256:e457a0807f9282d4caf3b4164ba8becf0e7f7b66ed4aebaa82393481d985c8c4

Manifest digest:

sha256:96d6835f9ee8df0dec847d5902a06ba584f8b12cdd5e28bb849050c5909d27b8

Size

44.63 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:ae00e69418f226a8d1fb097dc751decd3a9bbcf5f77612f20043229f7a188f1f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:3cf38a8ac4d68d3bd3deee3e68c3bfbf32fbc38a70175b90630d6feff2a94d67
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:6e5082fb773cd07d63e0e7802da3a772301bbe73a3a5bc017760e2e4a79fa4f4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:a04ef7110d2d838e5d8b5797702c4cef7428b2291a501a70ed4c8ad40dccf008
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:35a6079282a888fe6cacc1d2e1a38a9b547cdf1a5935c88f47d299e23df567ad
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:4bf64883be99ac9e25e2f50a480c188253bf6f94c31aa75479e6881aa03da6c9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:b8cf1e6478e5215747326f3498d263afbf1ab0bee6ef66586c98ba8ae21ee519
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:bf06e349b084fc7be61043b83942b123b91d4d88da93368433d44df4a8b16ad4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:cb9a91b52b4a338a6dc74064d93319914b83234964ef37c2fced83451ee41793
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:74bc877dbc70cf860b1e72e38641cbe86e4a640aa22873e6ec3d0ed734b2b615
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:8907fadb232f917de43bb9212c5882c444baa8c8cfd14b3a6acded7c46ab1d54
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:1dd6076d100397e48b723d0171ab42cc706d13287ce5f11b6eed720d54760b8a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:6aaeda102441871aac3551c8137bea15cf8b5289b4592514010b2cf15dd1b445
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:0c9cb47935e93af0409260b0a36df95057b6a68fc15637d496ee9cb2cfa45882
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:b636704f77bbf92f6d31dc4a98d00417b3b4077d619ae4de3c629f4f60c970af
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:9e3e41bd17704a272fa9bd10fcb2191ff17dc9614c051a401aeef975cf9322d4