Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

10-alpine-fips, 10-alpine3.24-fips, 10.0-alpine-fips, 10.0-alpine3.24-fips, 10.0.12-alpine-fips, 10.0.12-alpine3.24-fips

Index digest:

sha256:e7f7ff6787c3f68b08b21faaa2fdae557b18240442dca69176befc24b24557f5

Manifest digest:

sha256:a1a0be090c42c9bf921ded4d9a269e2cbdcc0870758884bf5efb53b9dc4a6112

Size

45.76 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:8a38269872ecdebfa8100a06ddd9f212fee7ed6681950e6c3383dd388b0843eb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:6fcd539fc6c815e6d9f09b17449c243fa3e4f424f897ac6d7372d5d4cad6005a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:b359401fb963e74cbb102b8c1e582c6718953e6148390c17a7f9a1d57f25947e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:adb01f773054d0607e18b318a70f3e95ee6d8c71b4b1617ae290a427b4d4ba5b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:624a6bff09fea3006051f5e09f7835a63b58e21cf44c90d93b477f54ff7cfd87
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:a0ad12099467290e3c4dcbc8ac024d35d088d56e176891f11fbf841c70f80b8d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:c7a2519a703ff0e112361eaca7cb9294c3adab8c6182f1267f157a56fb8f9be2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:adc0bf3133cbd5cd788c24946a1356c7f17eacd0c4d9791c60fe987b0eba3732
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:cd87c13541649872bef33a202c72243ea347e8f11ba2b10380d80b77a0ac4bbc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:92d23c9f2ac61a4099a87f860bdf2f70333f93795aecf252b0afaec37a856cbe
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:54a7bd5c955655369ab9b6997133937ef5b0560544cf4ee1c14e1689f7abd2c3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:9a349eff663904aeead6fcc9dbe4a66fdf4a04bbe1758ff8f5446de808166254
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:1bf47fda1a22aefd5b6abea4e268cd80354cbcc34cfb37ea2da3b325e33c33d8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:ecabb04ff76f08ef1934c39a6a1e18e0e369228e8a6761b4eb41757b5c3acd15
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:91a191ceb4217a11c91e6acf8e827a76239d130e68bfc7417bc4e582d3582179
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:80d3c4cd168a74b165dde3b4ce82868df47dbbe0d3ed4cd032fe44de50f7bce8