Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime

CIS
linux/amd64
alpine 3.23
Tags:

10-alpine3.23, 10.0-alpine3.23, 10.0.10-alpine3.23

Index digest:

sha256:3e3a424fb4eafce97aa53580135f3a29810169e739ccb2ab3d31963a53a629b4

Manifest digest:

sha256:4eb29b6dae64fa0f0c92ac5210df25780056932d691932b43d17f7d3a54c0b87

Size

44.23 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:3b0a8265639882a22a73d517f134853279116a26ab653e436c7bf628e3fbd363
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:722c903bc97a090a8a758a1668f85fd99c5b531e24037fded2fb85c51c2ee024
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:46d63c363c02c30c4c571337c567230c35472c60d9710d23c318560bd0af6816
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:c91eec35888dcd317ca038bd248b4fe4f0934afcd90299707b5505d9424080a5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:dfe34b0fcaff9276efee596b0d4f04e8d9c06750a2b2451ce04bfe2d6321544c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:ea65af737e5e39782238eeacac5723fd242007aaa41a1f9a671bf28392f76958
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:47b60b6af36befbe6cc7a8a4a2fca26caed46fef571c9f4ebb3c481e432f072d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:7d304bb3fc9a71eefcd93e5236741ef72e0747c63da3a96bd0c15d1332ef15bf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:e02194b1effdcf6c3532f5fe5ddd6425e825c8dd2984b9763c05b5138ceb3421
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:1df29f7ae794355548e31361dffc4eb5b8d17e78a6a9a67b851b3e5e02a2ffef
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:62678885c1fc3b3801f5855d537127e68afb52b87a3aa3f78de3d807bbad8770
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:0edabd8d450861c462cb8d40afc45cdbb678abc4c48442571debb30883202421
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:6ee0bb28b4bd902efd30745772956eba5fb0088bb7d9ea435ea875a7fc3c8f18
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:bc2a40fbbfdf334fb5732e02ce8b24b0f4d832cad70192ecf8d777826e432bc2