Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

10-alpine-fips, 10-alpine3.24-fips, 10.0-alpine-fips, 10.0-alpine3.24-fips, 10.0.12-alpine-fips, 10.0.12-alpine3.24-fips

Index digest:

sha256:26a07b938946b47c3cc374db9779d1319d6918feb75532cb52553654e9e9f826

Manifest digest:

sha256:a0a03857a95db1310ea92f769b1b2b2ea88d5f8bc2b4b0b851f97c8dd8686140

Size

45.76 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:de58e559ea85c0be9f84a06f30265155b1fb8170059e688a0f465df9006c8ebf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:bd7c6347b0eb75c22a349c8b2ee122ccb1d6be9afdf4cf6fa8c2289c633cc4a0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:cf88b0dd4c899ae65158a96bbb1d87f34918c7db22abba194b6f8d1247c62bc2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:c31dd11532c7c16bb7a09fabb5dcdc1fdbc4b7f6992d2216978ee840b883d7ab
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:a5138be65082c52f9299260d45ba59f5a3fefbcdbc4b0776cee332ce6f390c5a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:1a78f9b75afc7617397e2cbb36a8bd6b370738bac745ad6a0e495d99b0ff2786
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:5acdfb334887fed6a8b693f591b1117475a1d7b446053d71360b6daa0b475a53
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:66cfaedf51ac7574a31fcf7f3522d122ee57ef44293c13f12b84dc19689ccf5c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:b9e5263f0d69647aaa563e3471b4b76dedc0d2edbdd7f4653e5b2e5eae1987d1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:98c31f5587ab159bbda1454f71a3afafaa2ebe7906538c7ccbad375a9fc82113
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:24db3587762288cc25057b49a2f54c347a0367d94d8804072735906bb990a844
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:b77118ca46e94e1bf4025c3c22de5b7d587b6a14618b64ef238964dcf25aa741
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:0ff85fdc17529067a58528b4d451be0d4ea359172c349d6350b7dd21f855439b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:b458ef3ec6058f40c1fdc6574a05f51068eb469105b450b259779529b08724c7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:abfc323233a64fccd24379a7520748779d616b46a19ef6b61729819474bb0f90
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:63fcd81c48847ce6e613e6918328629c21acb8f393d9cf0c46f4e372f8c5e91d