Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10-debian-fips, 10-debian13-fips, 10-fips, 10.0-debian-fips, 10.0-debian13-fips, 10.0-fips, 10.0.12-debian-fips, 10.0.12-debian13-fips, 10.0.12-fips

Index digest:

sha256:0befab5cd964f9d89a85643d8ed600f2219b2757eca60ec9346fff8a7c766bc6

Manifest digest:

sha256:1c2cb479ab3f9307317afcc09d58c58390504d00e5424525950e0059a38ecd06

Size

53.17 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:09a3e67f2481234b781f06f74b8a5293e68e70bc835667a7bb81efb43a034905
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:54167da42a56b14b744c4e7cb220bcf82664bf09637c7c9aca359d3c5a363df5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:334c6c6fca3b719d2e4267e1b8aa309a322f3e588cc7c5e9be5ab159cd22002f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:4ef9aed35913b517a1b7c1f3401a3efdc22c3d086dbe73311c9ff7127501c343
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:8ea4a2b8c706bea9de34b05852100065b32c5978c41145449874148751183299
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:40df1ed16489124f88a00567b872a41341078fe4ad68017513acdd799018076b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:87dcb3049fb99a505d13e83f313d08cd9a5dcba046cd8740fb897600d657fd29
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:b36f126aa812fc8b06085ec2ccc49f52ed38b76c5095641f673dcb200680f62a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:e23a81884a3435ecc77ffdeef18b42f6c50148f8568e9eefb411708470074ee1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:8d6baf12b255fa59012607c92dc3742df1b5b561a777c409fae4e72e3c18829e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:f5628af5337c24032baf3b7394a8410781a603f15de7247dd14783dada25ec11
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:4fd42b9c4d75da10eb498e33e209ec506c808e7f11af101378e046971e491780
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:d8c2fc316b32417b58603f2c1824bee63918eea0025a1bfbbabab2ce2e21ee2a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:2644c87d1d9c5b643c2967e1b8f150823cc8ba787f0512262e9e820e850c1ab5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:b9b73c4ed174f2aaf6575b6962618df3406552bfa9c15e78ad213e4ad2ff7dc6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:4e487de1cb233900d81b6dcc8dea1d9ab81df6dc12f02fc9dc90da700548c834
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:4be78a73b1a28968dc902efc74f3012bccebdde5e83ec3758f2cc898e6bb61d3