Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime

CIS
linux/amd64
alpine 3.24
Tags:

10-alpine, 10-alpine3.24, 10.0-alpine, 10.0-alpine3.24, 10.0.12-alpine, 10.0.12-alpine3.24

Index digest:

sha256:fedaa0af6f1f519bd4b4a1a936d72b0d0c21f71f9f7f915f4699bafde24781f7

Manifest digest:

sha256:26305cef2fbb11e101d0354b8d0530d318649168eb10a99cbf872aab219c1e24

Size

44.61 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:f8abf1657839e2acd94ae5dddf190e29d9709e85e96e6648c6c8f3befcc0d523
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:1b64140612f54ed1adf46d4972ab7bfbb54a837bdb8359db2e66bb14bf74f9c5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:ae4d66261144c0be73cb7ddad47aeb6513c65a9cbbca98cbe364508dd405d8c8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:755a5846c8ca6b49e9c568627d24f363358172a3ee4ad152a86d761ed7d14a81
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:af9a278b48aba4b1456c54467b9241fc16d33fd5adca280f94d1adbdc8ba4a7e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:ad6ce7120c42aa16565b3e2cdb6117cae5bbe14ff4ade972ac409ae7adc35554
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:6950df98436987841bf3318f3f5e2712b7268225a36c1d312b828fe973c32560
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:47cef3dbfcb2c9da307762ba50c7cce2a413779863f286e08f3c5bacc52c2ca1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:3343dca5a66209bfd07bea762f8b7618e4796623fead5dce0556548aea0c265c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:3cd6bea2e38fd7f9567af371a8716712e30deda55358c595b3e694b11f1aeb22
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:675b2bfacccbd461fb48f5ae49a16f9745c93e3dfe2ade1386d106753bba9b1b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:c6fbd0cf34b09bab5a91119b793c6230e33621d19942d9a93fc78593d8ec4132
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:b7c848bff6003a6617e4eca52dfa2202fd23533809d7d5a58dea727783d7aa8b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:50dba903a14579ce75bcb571d5d3cc31e1df6b86cd7656e8fba39be3b25e718c