Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

9-alpine3.23-fips, 9.0-alpine3.23-fips, 9.0.20-alpine3.23-fips

Index digest:

sha256:a1622101c46a6e111ba5ba058ed2b67eb34861159692bf5cdafa1af80040c566

Manifest digest:

sha256:c561eef0b5146a3aa70881ecb5eae5da0b95fc609bd9591fe3ee9185426e3d19

Size

44.63 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:b2b133fb307ff194d3c5779ec766005465d6ee6d18b6ca1458d9515877d40a14
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:cffd67a4a0aa9f8a567592ca03016966946304a8298da33f983638c20de2ec9c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:0a54beceddca7acc2dc0c5676ca53675b4e425db24608a79e8570bd346b857bd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:c4f381c170aa429223913e955fb82f38530c8baeb5b458e581eb3aeea933791d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:35e406f14e38660e94011e3c13ed6d3500d6fcbe30e185fb45867f5b9f6ab2b4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:a0cf49a88eda97947959b9bef83e67423d4370e938464c33aebb3ef44c4bb3dc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:84bb9080447d0e7eedaa5e7e2fd3edab4d052e4e24594d629d223866b8526ea6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:547b288399ba328da8bfdd2cd368eaaede65b8a8c32080c743f689ed7d936d3b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:1b5f808558aea6ced7c2e2da7fba0cda24c3be69b36660e380762e2f95a5cb6d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:be69d8607e438de8cc4078543b56a79c8ffe6e763470319b437266e1ac9191e6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:5777b8173f35ece8e3458d6b8746ec9714b484e5ced1604fff00881273acd6f4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:884d1eb7164c0a5a616c2ca300d74febaaf0e1210aafdab20af958797627204b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:0e3c594057e86ab0f8dc61fdf4c8b19efc8a0526c392e1865789d2ecd1b75c79
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:40955f7f4bcd3d560eb62cdc254197a76f8a7a6feb9ce3624b5399148527ce3d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:cb3e2ae4cec8ad99550d5f7e730f1b5d33db9d3d118f8b1e463e4177e119f75d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:219903051a5f21f8a7fdb2b9ce24e776285793ee4d5db4d8803611aee04bc9d9