Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x SDK

CIS
linux/amd64
debian 13
Tags:

10-sdk, 10-sdk-debian, 10-sdk-debian13, 10.0-sdk, 10.0-sdk-debian, 10.0-sdk-debian13, 10.0.401-sdk, 10.0.401-sdk-debian, 10.0.401-sdk-debian13

Index digest:

sha256:609298af60c05f5f66f625f72be8a8730aae7d58aa15f74f355ad9a5c7da9797

Manifest digest:

sha256:f5673c533ff95efd1084bd6ea646340373e760554a67fa92a6dcd33ac5752617

Size

242.76 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:64cee26a482f422347c0183b3315dd50addd4816b6b7a6cb9a9a6f2a359b7cb7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:d70bf9df7ef6e7589c4de165ccfe39fa485032fe89ed02650e3392a6066daac9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:eb9c3e9cf5372004a57b61d4445005f7c2774bd69ad0a3db6fec14fff9ede2cc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:493e69b0d72f2a999390c2961db36d37e68d480e3a29e7eee9774799bbc45e58
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:be126cf1b8c190195f91092853b0441ed569f630ad59693ea50e6745d9666e99
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:045a6d77438aab53e423d53882118de8b2d1c2b9f8e269602ae82a5772de60b5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:4e00b0cff36a81f33a4b107713d153146612c4a28b7ca169c739cc17a8057969
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:e88a7aae04e51cf41ebdacebff278708a64f5b0ae48fdb1c898810622cbc771a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:bbaa6b6625b9947e0b9656ca07eb6cbb89b48338a08b82926a757e469267017e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:04ca0731226d556a8f80097c91948dbfdda05d323e5a35c17e30bf76e8786595
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:86ad7d76c7a0567fa01013b80d2527055a1e64bf3d479db8458cbeafcef672a1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:20490273fffa9fa71453764c774e5dda3a28f0a37503a730fc1bccc42a847a39
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:76c32d89df0d7c03a710d9c68b9320a7786ea471a51d24422e9d0ae2968aeeaf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:d0d173c51701ec28b4aa3280aabd042cc6c44e20db98bb4a613ac1451a60bdcd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:f7c3ba2430baf04114b447838b19d0f5ca9733cdc287b0bb3eb6f92e18e77a2a