Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips, 8-debian13-fips, 8-fips, 8.0-debian-fips, 8.0-debian13-fips, 8.0-fips, 8.0.31-debian-fips, 8.0.31-debian13-fips, 8.0.31-fips

Index digest:

sha256:0b048f7859ccf351251e9118b2a6bfe3738c9bf55e99ac7e3a53b4a6b923db06

Manifest digest:

sha256:23feb6044e317a5f2905a4ce3fd54be68a1c4a7e8bb9150bf54de15cc7f2ae47

Size

50.12 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:d8952fa1bf5328e4e7a410e294b5a0832f744a8876b8a821a59b42e956156a4e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:7d554864ecafb6839b215f3fc1b138ac939064080313bcd29216f0fcd4918224
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:b710f23c6db7d82f4a2299b731d86c08dee65ee1894739f28558cd4624fe34d4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:df0a140d2244ca4dd1edc55af76f62bddf82bfb65f6780e9bcbfb0c8477f4ca6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:c1469c1b9e99ec02d467f381ec9a28d151c53643c6b6a8c457f5ae7fcc4f55d6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:4b84114011448ddc4856d74384a2e65c61ad0f51c8a8c46c815454ebb981e9b5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:622b82023409f4a1f9b1c8817432529f969ea993ed834de8c473dc576ad43e94
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:0b3fab82d3f72eef9395feb32d97dccf7bad9177f638f38d0554c19a863aa6f5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:1561b9f4071f9b3b701a5be89596c247c489b8e66dc7706c1d94e08bf304ccd9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:be1ebf83b4b62449f45c32e0cdf2ae2d6076d21e441d3d3fdc43cc053feff8ef
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:48ce0e2c0e8103682ab27beec4fd625a86b6430b93790177d1782b03e7cc0fc1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:2deb3c4e93a3f2c7c882412afdcc31014d3e53443ee0cec406f853cf66d3ce5a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:0128dd950ad5aa265e99e2a6c1c01e8a5203e5fe161cc58634cdb45f50e7b4ef
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:31c4db0e93c141ac12bba8e049eb78b3f880fb68baeed73c1bd98f4b52a01a23
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:07ae2120fa410df6c5993fda7f05ffa53850a8b9d9966c3740daba1044b8af75
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:e0574c592f5707764becbbb9d767ad5bbe77e9ae23c0f9a2cd4577e3d5f5acbb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:03bc03e15fcb110453e59134b30ce2f04f1dafa31fd5e2f54a16c5c6d9ea231c