Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime

CIS
linux/amd64
debian 13
Tags:

10, 10-debian, 10-debian13, 10.0, 10.0-debian, 10.0-debian13, 10.0.12, 10.0.12-debian, 10.0.12-debian13

Index digest:

sha256:2890299e30b9e05cd9b567aaefa2e8d8f8489bd63357918fe17cca4858737c40

Manifest digest:

sha256:f22e0826cf76d1927e4f5a423bd7d7fbff18a2d377d590065df176a17f74f2ff

Size

52.39 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:c6bfbd6c1adeb23b310056a349472ecf8d5d37ada8c1b7b27f8299aeaddad890
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:7b5b84b290f469b1e95e081f75ec67e3204de2ec16aa1e64b9c7df45f59bf9e0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:b4a8089486acb8a7fdce28bc13cd418f25b3e3deb5e34780bf80b814da518d28
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:9325494c69f1fda16bb2e2efeebb3840e786de2354c6586e4ca2dca93a9686ec
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:ed56c695aaa8beddca4a25123d0108203e8ce9251070c965396ef7d3cbcb53a4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:4a659a72faf7b80373ab6c35dfa72c0fc943089048609d03da203758e75f41ed
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:b5accb8c8b325c9b3534a0820ab93432fd2426585d010f2c41da76b55f02fa4e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:f5a5eb212391b4a3142b96fcc86373ea4c6ba3ae2338b03b5c58d932015cc305
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:122cf758d185aafe26ee9ac80482c88b08e2845fd9311ad622701b8996de3395
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:054dc1244922a5ec16cfb5cf5a42bb295bc418542d5e13a90ee356b203fddc6e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:f54a832ed030c7d4001ba40e46d6eb303bb1de4b75ebc4fa170b0f575b34e4ab
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:823c8eb63cbcefac5fa1d52e2d406a0acd253ec979ef0f331fb26e72b225b142
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:6e4d83aa878dd034f5f487e73d547fa92d8c020074a1099c1025b639643286b9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:8fbe53c3c0275c43b3fcab3aad5e937850a66b4ada63000ec8074f9533fd47db
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:c6928414d5df96f08d27675c5da0885583eaae91dfd356db5b4ef396cb6f4645