Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x SDK

CIS
linux/amd64
debian 13
Tags:

10-sdk, 10-sdk-debian, 10-sdk-debian13, 10.0-sdk, 10.0-sdk-debian, 10.0-sdk-debian13, 10.0.401-sdk, 10.0.401-sdk-debian, 10.0.401-sdk-debian13

Index digest:

sha256:be5089d1edecd340619dbdebd8c93686fbf7be95aff77c1adae92618ea9ac24f

Manifest digest:

sha256:e2dd03f4af09ed227c2cb21e55c85222fd7050eb91538326b31f6f2d0ad13e74

Size

242.74 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:13ebfe23f379960405588fb682a33b935da2bcd9f02ff34e1eb89e737a4afaf2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:2a14545c352b2001e9d73317b8a8820e050e788214285719e0cc58afe6826156
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:2849a7d2848b1d4603d3220d2cad15cc78280083aac1ae63423efc87bc1832d4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:365a0d5f2e2cf65bb4766ff79b388d740d2a54c9fdf5ee4afcd8429f5731cc7a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:2a897c68ec3590ec297130f7d798744825400519dea858108fc706d06c387498
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:e731585669299a4b5aa3ddffbdffeb26af225979a938776c455787f5eb6ac14c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:5d1bf56b8ee7647fb047b32e6964ae54dad974927e9fca773a4f0ff94e1eeb29
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:516b20f186a0265a75c15fb93c072f7def02af8d86658c9e31c1ec43de8340ed
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:ff5c8ac4f9124e40168b753ca225e78a4eee802ca575ff42ca51a6228dc5494b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:1098e3e4a2a999237f28209dfd257bd3165d4b159744671aeba775f7f021cb67
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:e7d560ff873bb1a673c0552f2627d2dc15eb6de0c4895cbc56aa51e4e4c352db
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:54d65817c95f6c58adf596d38bd8ad824db3f0fdbd5c2b0e6c5d45b3b9d60816
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:9050f97f2122a3d3147ee5a7f73010fa94fb919ebff1caf38f8e5a55baae6e8a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:9e7840b88a3ccfea2868d4478bab8bb89602edfb01beccee9488b0f9bbaec7d8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:f00283bfe9869237e5f08fc6bd8efddcd94d47d98fa341c24adc9c62a38dc154