Sign inSign up
ASP.NET Core

dhi.io/aspnetcore

ASP.NET Core 10.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

10-alpine3.23-fips, 10.0-alpine3.23-fips, 10.0.10-alpine3.23-fips

Index digest:

sha256:c7b1b96b5c8ef6b2564aa2f3c2e40430f18a022c3cac7f6534928791b70ce51c

Manifest digest:

sha256:3002a13f6c200fe507ddb37e2f3bfb562645e450e643fa3d30ee2031c5fa0007

Size

54.56 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/aspnetcore:10-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/aspnetcore:10-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/aspnetcore@sha256:9b62af10a80ec33336ccf93dab9feed3606beae3a942803e78e74a288c7e5693
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/aspnetcore@sha256:01a6b464ac9afa7a1a16f3258bf75401338034a4b87d1e592f0c5c70e11f872f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/aspnetcore@sha256:dd49955c404dad72a2e189e5694f695f47802937159e9be85881f0ea42f3c821
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/aspnetcore@sha256:e5257ad58b0c798326eedaa7167a9cb7da887b39178b744a92d5137acb42b2b1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/aspnetcore@sha256:bda24d0f520bcc32995c991419040fa92457da6c44f4a88f1cafda9b07f06556
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/aspnetcore@sha256:a8f38b30d7e2bcadd38a95bcc935dbdf6bc4227a5e5a80bc6ae532e176d80910
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/aspnetcore@sha256:0b5d8aef5289ab5d421edff9df4f74bf94300da84ba9188aa64892d359021eb8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/aspnetcore@sha256:cbf9f00ee7dcf96b797b5cd746648915b31682ee623540875060e6c0ca1ec8c7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/aspnetcore@sha256:43de3a8c0a99b3b58cdea0d6a167022887d27c078417fed4e02a1acc9c3c6746
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/aspnetcore@sha256:f019a47df8badaa4adecc1cbc991da317b484310f560341ae5295e5009b3b591
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/aspnetcore@sha256:5ec5d66b86498ff729bb643793be5a3d938c8ce7fa984f57a88892df2ce982ad
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/aspnetcore@sha256:ab88f4a964e444b6d94bfe3aba4b27ef6db20179aeba29f98f3d216a3dad3914
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/aspnetcore@sha256:ccc2fc3c2fc96c52623d746b30a743a646e4bf62785d3d20531b2b069e551b6e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/aspnetcore@sha256:4d8786020a49fb10b6fbd2811e455a9eaa128247be20672ef30ed3815d909987
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/aspnetcore@sha256:fef5e749de7a64cf2cb0b20a100851c9ecfa1b3a376b72a8df23b535b47a64bf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/aspnetcore@sha256:9a2e7ac29f8bd89175957bd3aea343bcb61ca0d22902cc008235a608c5c34c5c