Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x SDK

CIS
linux/amd64
alpine 3.24
Tags:

10-sdk-alpine, 10-sdk-alpine3.24, 10.0-sdk-alpine, 10.0-sdk-alpine3.24, 10.0.303-sdk-alpine, 10.0.303-sdk-alpine3.24

Index digest:

sha256:1f6181a3eb314edf5d3df0120c21d4395bd67c20bbba874c8cf384f53e33e565

Manifest digest:

sha256:d8105f924282134b47dd21ae7aca3dd4c89c0bb49f41177bd58bf146c868b527

Size

217.21 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-sdk-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-sdk-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:dc189c5ac954047214e7a2ec4a8a095862c54075115299679d6381b4d56719df
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:2a0c7c543e7ef45f4638bec8aaa34fde18be6a345ac5aac1756f6aad557eacbb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:9fa46f594a7eaf607c6b79b683b9141d4cfde02f54223168035da14cf1e93db9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:474fbd0ffa3756aa44321ae799c2947e8afd08ec29693169acc8924226a5ea81
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:26a0740b5ba2fd030d72c398e6690d51631af7ad2e73e7faa994c9fb50ac6e36
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:de1fb4f40868682181804730de12066846c812011c68ed1989f21c82c325ee84
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:12b4baa490cb00941e0793acb30a6d2e8c40c879b131b69233efa800dc7ce3b3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:4e59f56a42728eda92970eed9a969c792e34973a8409c34f244ba05048d9aedc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:c7dd1e5c3b52cc6b661ae0525fcc18791bc03905a65115a702fa8a4110d3eb15
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:dc6f4d68c42fe0e1a53b05fe6525d9fe497e2401956d91b0330547dc52d3942e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:1c70b710ca08fba0e2f4c7bd6fe6824c2cbf30d6f72e53b142822533d6e6dd7c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:bd2bdc12515944a570657565fe1f1cb7989b62c46c74cc0d72099f58118878af
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:60e82e3a27778b83317bf069d214785fae841075f88ab70dfc6933bc370ac900
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:10e4acc815eb3567eff96ee344bcfdc83752d4dc3938bcb812a9e298e859e6fd