Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x SDK

CIS
linux/amd64
alpine 3.24
Tags:

10-sdk-alpine, 10-sdk-alpine3.24, 10.0-sdk-alpine, 10.0-sdk-alpine3.24, 10.0.303-sdk-alpine, 10.0.303-sdk-alpine3.24

Index digest:

sha256:f7d31303735b6e49ef17f8eecda4603eb53799349ad0b8079e5c54cc4bce4539

Manifest digest:

sha256:1cc5c0bd26506e71bf92633450a685568e4c2fdce0a673891693368634d0d6ba

Size

217.19 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-sdk-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-sdk-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:a297deb869930f44c6c27ad273144be15586f735eed938939aa126d3a0a35cd5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:8b33662a20fa675182cece0377f0ae803f70873bbe2b4a7db0e6d751dec26de9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:6c285ddb390c66eaa6c2065194e33c4b749222ed8f75776d972b86a41ab87ab6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:c3e70010df0dc1b4a659addb30842b5da1d0eab1663b7478a72e7facc45e0bf7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:958642675733a63f5ab5c4f08832ebaa75e7d8641de492b63943420d8d4df7df
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:68d0c4ad5f5d6d037f46531f70b8a10a9f21c736770d8302a506d158fd7678d7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:c1f5081256ef2b6d83d79b839341261f461e2ff8cfc49f88c493c03f4092113c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:9a2dd6511ba911fd1915424bb5404c3b5def0ea4eade90565fccfdf903249e1e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:c63c2253ef44f490ccdd80b542cace1770ffb7c786ab6b15b2c24edb7626e6e4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:38611a082720e1b6f8fc2f35f566f9e0a5dcd963f574d20b41c2590064372aae
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:5d883a39a8ecdc6b6b9aafe456e45c9953e481e6b6db2625bbdb662acf560348
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:a51f298d99ac618fc67207ea85fd7a7f714242e3a753d1ed619400dd668be4f4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:08a3111506b37e0212bd1ebc4ae6310125aee2d808d61510c7dea9f818f9181b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:3406aac344102a8999bf52037802e4008a0fc04d81ba92693bb6cc7bf3a10f13