Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

10-alpine-fips, 10-alpine3.24-fips, 10.0-alpine-fips, 10.0-alpine3.24-fips, 10.0.12-alpine-fips, 10.0.12-alpine3.24-fips

Index digest:

sha256:6fbc4dd4b30067aff4aca7967fcc02dbfe1d60256978e6e0ed8326222498e579

Manifest digest:

sha256:bc9ab73dc93d01545bb9d37cb91da823cdebfbf3af27b512bd64fd9cb8e250ab

Size

45.75 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:d50199fc94d98c05d1d3bb52b82ff048c6f5400057d3dce63e5f5cc029a0dd58
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:c95e09412333e216b37863d4c4ca6264b3ff3a4a2f16d30da2f81dea3e61cc4c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:c1af90ffac8a3384ef5dbc156708c5a92091a856639227f8cc1122eaa83c010a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:d6e9c74b91d8be3daebc6eb3a767cd66fb3f4ee48ab40d972aca8ce9eaf79245
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:0ceecb769eaa75f3d7bf4bcb7b8873c3035d81541d3823c82c5021e5f05abccc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:1b4d2a55b9a9a658df518205cd8572f799b7bea3b4108ac8f43be0e3c135e612
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:8ae22b1c7bbf4288c42bd761cf631ca737f5949bd05853a31db51504756e660f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:d7261eefb85d494e4992cf9f01fe40ca755779edf7def4ec6403b49f2c7ae2ae
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:81143aafc057a9207e59c628f40f6f37217cb8ff5ff44b3251b377fa39f4d9ee
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:5feeea913e0c1a9d0dc55db954950660b1187e060f1acc36ea1f03e4905af456
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:3977249a1903c46801f73e4a9c145a57a7396874d868ab0160ad1e40633fcd0e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:aba13432a3757458d1033485cfc93afaf1e0d3cdbd2e4974fd61d469fbf12b8d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:88a591c69415f7532b934f28ee2cca25753620d7c75efcb608571111f529ded5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:77062bff85a55bff57149fce76c1886590ff7682ed26683f20611ce078d7283c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:afd11a1afd60232e8fdbd36fd19be2f08d887617c36eda68c01d6955ab10e30c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:19648a6ef3815dee7ef509c2cd33fad6fe57b550b6b9dcb5f962694b0808bcfb