Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime

CIS
linux/amd64
alpine 3.23
Tags:

10-alpine3.23, 10.0-alpine3.23, 10.0.10-alpine3.23

Index digest:

sha256:beb8b8eba864cf93834a1f8061d65ea7c2fc83e210d1726227b0765d0386ce38

Manifest digest:

sha256:1c5580d668e6760df0d6238e1159026946a0e303a1412fe518564fea322cc773

Size

44.22 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:1ecedf9fbc977ed595d878fae499d243e4a6ae074ae66b81f60f4454081a6c78
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:f6174b3d1c930288bf06bae42e1412953a5162d803b0041f1e04a9babae89f9a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:dad4c014b7ce92ce2dd60ab1310dc0c48a08cf03175b52f21e97ebb30a9dc5e6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:129d31ade97c5f85a0684d38f4a6676cdc54ad2497dade929de9bb4b47ff06ab
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:d45fa1c8c19e415849e403a62218ff197fd3ce9844f2e96263a3e5a5b6095b6c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:dc0ae7009c49b14bf5f40c81331c5fb916d818aeefe059a662666694fb8a3610
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:2466d1282012f22afe3763a2b6a61a0eb71d305bd67218d821335afaf5d03ee4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:eca7532720b0b47a5fbf392c7ec6aabb91b3113a8656099930e1fe6df63e870f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:2b2b569dd8ff3ad22ab15d41877ee2afe7972af5a81731d227949a34be2e7074
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:c829f82a5798b9cbf38ed78301aa598c6c40fbf7d0db6f41b50828958254d1ae
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:c53a7521351b4910563e10610f62621dc5fd3bc7c0f3fcdf725c835ffa2c5605
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:ef3d1fdcec20bc4168b6509f9fe54779dd26c61dcd228fea172eb1fad6d354b0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:9621cb86efe4e1fec61fbaf4d43cfafbf49d39e25312915ae4dd94e58411e107
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:4f9f4886fa2df37d2a8c915bfab6b38b1efaba76cb574dad4571ed2fc51d496d