Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x SDK

CIS
linux/amd64
debian 13
Tags:

10-sdk, 10-sdk-debian, 10-sdk-debian13, 10.0-sdk, 10.0-sdk-debian, 10.0-sdk-debian13, 10.0.401-sdk, 10.0.401-sdk-debian, 10.0.401-sdk-debian13

Index digest:

sha256:c44ecd51b998061aee7d12c547606eab6161f4b11d96a2cf124b1e4ae6078e72

Manifest digest:

sha256:047d57e2c38b051c5411d549cbb4ff96cab12c098b099540e672415981afe245

Size

242.74 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:5eaa59152d749826fb10a4fdb2c6126d4395d4f086048b1cb073f29a70539847
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:87ca31cca46d7cc9dfa031fa117cb46c498b9f45361b8431aea610bc628b0853
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:9fe5ff15cc38a08861c68c64c0b5f428fe14fdc49d763561619263c327ae091f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:4b890d0cf0963c114d140f9fe17a6fbb36cc451d04f3b870e5c0d28ae9aa4f7e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:c3ba2581602f38eef1ba784d75001149d75596ebab87adb822a3f392617214e7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:b9a8bf0928411418071ce581a839fbb0ed8d1d091ba503d63be294783776480d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:de71130439bfc8320c845a207977260f59db24f382ff83f71e2296b9aeaf6f83
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:9e728603d651db885b242df118f812bbc70dfae6cc17ba9b52c73934549cd720
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:45e8cf2800b9a4cfbe722940df7bdbc172356177fedf43a1e155c08fe53c0df7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:51ec90e79a3d4f7964404af39b0a241df50d6630a5cd9f0c29a95da7db7d5192
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:8193fda948397a740961497456289ca84a0173d0c6d4bb84358949a0c05c2eb7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:106b287c9bb2c8e7cb21b476964469091bea9ae678249ef1ca875f98e9c72b23
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:f81a3bc6aad218d0134a9ff02d3b6d31a3c3eb40f2c29f3353255ff5a3742048
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:2b88d64fc61acb048e12c16d1358d3e190e4659f9031f444efb7d1087c535002
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:70a7aaf7a08c5adfb990a4c1ec244a603260a5695e11879f95406b5b585d3059