Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

9-debian-fips, 9-debian13-fips, 9-fips, 9.0-debian-fips, 9.0-debian13-fips, 9.0-fips, 9.0.20-debian-fips, 9.0.20-debian13-fips, 9.0.20-fips

Index digest:

sha256:20439c5f52d9fe07fcb1923e1473f3dbce9bd48b53a5dc6f1eb394aff1fa4635

Manifest digest:

sha256:dd978f33ef75dafadb58d349077883047995a02cb345efd607e9215bea97f82d

Size

51.88 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:f067eb13c2ff987799b63c36094e706fbb56fce1d8525a8ce4e6d676ecf4fa6a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:46beb1d65a6f6a85ae66b51d0477a61bc88c2360964956baf23b81734ed154d9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:34bae6fce3ea8a7e1c38705396b90ccfa4247cfb1e46d1bc622974282643d20c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:a68b4ede42956d1d5ff6bb7db4fc67ccc723621de6c502dddd0c244a8107acd6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:8f0bf349aa6af2a25a848decbcc71421c6d1b987a1f9d2206b9d683a02bb5c07
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:106ac1a643fb16e00eb270f716da4eb92159a63cc4e3868df3bb9cdbf0e5a28a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:82d74f7c09b9c6fcf061767d3411ef3d80e80099cc72d78a17da8b3ea09dfb4c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:5b7459bf52f3e668431236e9f30deabc64826e98f2a4610e89536f69691391bb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:9d66e20b7dc52bc36dd79f26c0b3fbfcad4a555b4713bcb1aae4d7e33d338605
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:47b3a08eed806f89b1b3f92f094014514796b02de09adf40194b856fe316b1b8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:064b228b3e66d9710d1b6e4449a1fd059e273c7fe14f7046003f766083149315
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:1e588551f9a8aeb323fe92ade57e977c20af325310b4fdbd2fbc823fcc95a534
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:13fe75928971ff6cddb5dfbbae92000230262ef89626a2b77e68696a397aacdc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:57ca0a577df2249d5864bd0de871545dd72067b884a93879945de88dfda153d4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:52467b6abd1661d6b18b5ad81503b2e7120d7192964bc152673f16c3a86386d2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:431472a693969044a5ff55e743278add7eccb90a758414811f61a588159028ed
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:c5c352b007c3992899629724892cf1eca0c0eac51d4318b9de6eb9c4b0651b88