Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

10-alpine3.23-fips, 10.0-alpine3.23-fips, 10.0.10-alpine3.23-fips

Index digest:

sha256:3d517c60aefc4df58c7576c705419853b2d927fd5a9c25cd09dcd6d82eff834a

Manifest digest:

sha256:3dd098441322548638d18fc0a5fec2434e2be1cd4b3ec1924e2d5d8ab3985413

Size

45.40 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:3da67a92f4975a4fb042e82076942c0091145165a600242f897160a08bc86856
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:9034e0fa8cbdf49ef72195677055d4c93d6a8293221f6e3703d01f804e0dce89
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:5c94309b5019a1ed478e46b131379b78cead869f8a659515b86ca3fd909f4d18
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:d8af08800aa7c06f2a42679123347a019a748b82898061277817a522e3af1267
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:a930057a51f6e661496c14c65b8abb07cec88230224b19c7d5a06cc508b66c78
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:260e6fb8aa7ed1d59eaff65f251b803c7246b56ca2eeafb54d5fd26014498c70
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:7ec7454fb035c5418c3d4274d585c04cd2978a0b9e7799584a424ffd38b678f6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:0829efde53aaf2a93aef97f5e7ca79045d0ee08e100df23107d1c699bee723d8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:0bdfe3a37ca6d6665fbe68d20459782246c142448efb798b198d7247c96563fb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:9d48fe4bcae4598e9e6becf220af63a99d3eacea0e960dc54ae2171072e7b584
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:6d85b936de96ff9dd3e957fb31134b9876e5c31707f176c25ed119570a0862ad
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:e5aad551ae35582f30421c90c696dab041a2d307eecc1ff27b83903723c32bef
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:d86e7f01217f404db030beb93496d736e3ed7e20cc8b14bf0e07b7c771ffafd0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:841d3b74f903e48642134d5de38e0d9c55f2ae9e8c353e2e0851980c16eca04a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:c9b85d472179b2109e7bb347b50be9625f34445f49e4e24b235ef7842bd0e1a7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:341f037df19827ec1324fda3df0bd1dbebac0e7bd0441e22bd93b2de3f66d527