Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x SDK

CIS
linux/amd64
alpine 3.23
Tags:

10-sdk-alpine3.23, 10.0-sdk-alpine3.23, 10.0.110-sdk-alpine3.23

Index digest:

sha256:3e354cc5af4f636e767e25cfe4e6156ace121706b6b9a2fa9933e9fa6a76ec15

Manifest digest:

sha256:12cea4d741ba98456ee3f1663a6dd99513c2559e5e8c251a6e278d72bdf9a4cb

Size

218.92 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-sdk-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-sdk-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:cefd8438197938002837b7c84f06e185301f3d16c48d09ddd7c7d43d45e31b50
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:0bc3e0be15bbe321f55faae9456295be4602abe94177d4bacecf274094731a35
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:33cd2579f17cf979f88369c5a1e5d1db05d9350feea3cb42943c6f2e4ed7f131
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:cd0c901474e0e43a3865624df7bfb32834ec53b6d6a204218a87c5bc5a6fbd68
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:b051a480d1e4ba2e4830089e2b30bf19c533359d9ff492d62d976d17b4eaab8d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:55fd11e59b7cbc3b89ad475af9be73258875660045a55863175fca9f14350557
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:dfcfa1ef22075387b28bcbb8fdd85400b8e1bfff31986d2db62f2fbb8ad506bc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:06a3be5e67a7e340ccefc364cfd5eec4ba19ab6d9e5c47ae2f715df88e2d4187
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:a75bb1b0e4d3cf080fd9a2e7bd0b5e6b3f15ce9d12ad8dd94ed2637d5009831b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:46675656dff7e066dbb64414d06d311539e897fd24c5123635bcadd2c936941b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:8bec0722adebb5f818092ab5baff26cf18f25d513e199d0d5e353d04934bcf57
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:cc09f641448533d67b29d4192b6ff2b055f2a8c3a2d03861063b463a83f754ee
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:8becae8a56a207eda54ddfc57f210bbd6098bd3ab3d15460506410c7874a8dad
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:ba52fa3439197680e32d421fde3ef102215f5da0a2fa1695fd45d68cb5ce878e