Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x SDK

CIS
linux/amd64
debian 13
Tags:

10-sdk, 10-sdk-debian, 10-sdk-debian13, 10.0-sdk, 10.0-sdk-debian, 10.0-sdk-debian13, 10.0.401-sdk, 10.0.401-sdk-debian, 10.0.401-sdk-debian13

Index digest:

sha256:f7991dacb6536812999c5bee31af6b86d4d28c4ea10b7528c9dab4341fcbfbe7

Manifest digest:

sha256:c52d7288b8ac3f922d2efd23017df10e8b4e12a275870d6f6f994927dcaec577

Size

242.77 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:ada155ad8c57523f96ec33e968cf2a9f74f170460da29e76a345a1af78172306
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:8b45237ddd19e9cc28e490909b068f0cdb35cd802b3fe45c7a7c0e9d3e4560ae
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:111b8b1bab3bc51a650c408d9843c4cf00abd821de808b988e17fafbb8138fc8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:62504102621116990e38bb5d89b899cbe87f96c331b33a5d130840aeabeb63e8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:fec7be5b9d383d31a403a51d59636a570a6ad85701becef73d0a488db1f25b0b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:7886c682a4896f258f3131a7e3fc7bb9821330be2cbf2e8e8a937850d8e70729
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:d0de85e8f46a4252576eaf018de0d6b220ae93b468953c6d5b6c4e4cc11491b3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:0f6d77ef807c6b0a07f25eb109ac70024c57fcf79df0ba4c7a55764d0bdc33ba
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:7024ffbd05c28c510fecd4f6ed1bfaf1ec81a3f387e3c30ae492ed2222d9ffd9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:e20f84786b86d66907a0c404a7087fc7c0e9214330d32389990a2b2534d4ead1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:6f36c25f18f5ee3569d9509520c746f373a7a10a5651afdb6b047f29175406c2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:ebf1a82775291d9f8dd658d39b4fd75ae5ca26cbdc8640c81c2c1677fecaefe1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:4869b0d06be63580130b8beb6c67a6932307cdc8f49739c83cff2728db35939a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:69c1d7618160b51f7ee699aab43c77d9d21b8dc58e54861064961a4452bdab50
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:e33fd6e506deec597da6cd1f0b2feb8d202e654ef913e76a810f54589c58628a