Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10-debian-fips, 10-debian13-fips, 10-fips, 10.0-debian-fips, 10.0-debian13-fips, 10.0-fips, 10.0.12-debian-fips, 10.0.12-debian13-fips, 10.0.12-fips

Index digest:

sha256:0befab5cd964f9d89a85643d8ed600f2219b2757eca60ec9346fff8a7c766bc6

Manifest digest:

sha256:1c2cb479ab3f9307317afcc09d58c58390504d00e5424525950e0059a38ecd06

Size

53.17 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:09a3e67f2481234b781f06f74b8a5293e68e70bc835667a7bb81efb43a034905
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:e222d26c4c9f93ef2abdbed12899151d40c3c8cb2b74fe9b85f3f7432b839908
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:334c6c6fca3b719d2e4267e1b8aa309a322f3e588cc7c5e9be5ab159cd22002f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:b014f28c43aa0af6b1d5f90e76ece67d74c31f35179a13c9f747991856fe247e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:e7e1f9253271c385a5b4c016629968591e23e514fa4b6192222e6e9be6203a14
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:58995afa396b2367429854b9786be120bc12220339d9bc946f6e960904188ab6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:9feddaa1f90c24fa0e8146adaa459d741650fa8dc73d4cdfbedb3237b8737849
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:b36f126aa812fc8b06085ec2ccc49f52ed38b76c5095641f673dcb200680f62a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:e23a81884a3435ecc77ffdeef18b42f6c50148f8568e9eefb411708470074ee1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:8d6baf12b255fa59012607c92dc3742df1b5b561a777c409fae4e72e3c18829e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:8c8b1e3eb990e57546a99eac52fb1deb97b8299c7c7a7d8058a2bf272c92b583
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:910e5d7e773f300d107169545f407a10c76be9ec7f939e03fb54869327044235
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:ada6916e7fa949ab0b99b4fdc17d06b4476c6ce53e3cf5eaa3b556e7893ee961
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:2644c87d1d9c5b643c2967e1b8f150823cc8ba787f0512262e9e820e850c1ab5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:b9b73c4ed174f2aaf6575b6962618df3406552bfa9c15e78ad213e4ad2ff7dc6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:4e487de1cb233900d81b6dcc8dea1d9ab81df6dc12f02fc9dc90da700548c834
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:4be78a73b1a28968dc902efc74f3012bccebdde5e83ec3758f2cc898e6bb61d3