Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-alpine-fips, 8-alpine3.24-fips, 8.0-alpine-fips, 8.0-alpine3.24-fips, 8.0.31-alpine-fips, 8.0.31-alpine3.24-fips

Index digest:

sha256:237140a60b1c73ad5e25fefb963469931ea7a2902d4010f3248cde9533d17f8b

Manifest digest:

sha256:304055bd8d361a718f0a3fda47b12a83e8303079934b9f6456aa266d39d8a080

Size

43.56 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:14ba95f1f3e1729b4e969682268ab7b079fb991322456692f7b503eeb47faee8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:6e6e72f071a4654e054998aa1c60e08409e7f36d44d01c6aba9fad2e21a07685
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:c656237c463324bff31171ff330115bdbe21e4c29f14851560069021ffac56a5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:d8804ca99e4bd5e0b866a5c2440d9f306f1fe3c88010f38428ac548ba8538b6c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:00f99713d367b7f423554fca5ee46a9293f77a186001f81a930910db5c1a2cc2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:ae0637f90f937a83669b706bae605a560d9ce115306c53f0d6853d1e346ce0f5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:d6d83db2a817c7e2812a69ee9c4eb40100a12e1bf5c154bfad5e6354cf9a73ba
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:156a91fc65c9d3278ea406dcb897c11aea289d36d841e98c22dd9d9f5f50693d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:556300284a9dc51fd911bafc58cdfae6f208f0da62fce3cf69f0b114469f1b80
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:e1cbcd0c2b6f9565cbd64923ff331765e0a3a6c53b97b13f00517c21272137dd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:1c9cd940c797d95bd3495909968eb69cc39ef6e0e9f71067b16b397a3c554d96
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:8c66265f2e47d3ce2e8ac2a39de3e4ef81661c48d77163d056c71480edb224c5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:88beff17845967fb4a2f577fcd5a5c3b98d48abd51ee0a1b48c71d40da4b141c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:c307c57a5d75392f53db75b7e2c808239e3f845af075a29b466838c425b892cf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:024033e225d10ff81d5a04894f68aeaec005efcea420a0d23ea2a7e2cf69b7a5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:17aa371e621dea9c4afe60f2426c45283d9880d214752ad1b956ee852a5569d4