Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

9-alpine3.23-fips, 9.0-alpine3.23-fips, 9.0.20-alpine3.23-fips

Index digest:

sha256:cb2c78c4296531a68ce6e84aae813335aa1eb7b035ecfe2503f14c70bfbc111b

Manifest digest:

sha256:e6e52911dd17fe407b238a55c2e572de14fa224bbe13788ad45660f203434f88

Size

44.63 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:f1937d57c96ec4204445c361292e908f6c9ee5205c7cbf7d571af4b271bc46a2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:a917b9eb7f3e487dbef0928c6f6567c49cf54a8eef598ba9ce7d3913a9f9ce8a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:4852ea8f92b43626f91825b2d51c9d636fec0bb1a854f23698ae394356fd4e04
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:81b37698a5866ef698f462b525366a0f61c721df9d05001d1e2de8a0c370b293
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:8133e3d18663f68c6d317cd6df79667364ab4bd94ef9ea197ef8a205b71cbb96
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:ed8d221560a69e6ae91527bb4b24fc803aa6df7496f773ba8424c46645f2b0d9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:c5e1da2e5bcbe3ca940811c73fac3e985046bcd19a41324932d74dbb75e1db60
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:dc9cbff1d866e368cb9a77ff5a61ee62dc9cb68ba6ec2ea8d9b7c41c7fa4faf9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:28b2f9a78e0f46741f6bff9f35ad9ae0e168d1edbcf6b4b3fa22c2527447b9a3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:441bcddc6312ee050aa999f8354a6baf29363eab844d950023ff2703b3a1649a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:8df32b9b229437ccf90d3ba4675ae52af89e0efad1840f8729b33102e99c1b89
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:7c614cc65fa2d525bd0d9a9de1b2b4d756e36d4db644069764d3a58271882c7b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:dac9dd0585ff13bbb009adc4a9b0197880a07a1ad4f72ff1d6682b61f6416ec0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:82e80cbf412012d4f95987fbb3960c9e6d9fd48ad14c98149bb8d5d1228d176a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:eb6e3b96a00c53b07d2ce7e3e5005c73030ece5786b52cd1a89c620bcfe94825
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:11568932f9ba81294314f1e7d80b771ff991f5e69b95508dac4dc68ea56b6c1c