Sign inSign up
ASP.NET Core

dhi.io/aspnetcore

ASP.NET Core 8.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

8-alpine3.23-fips-dev, 8.0-alpine3.23-fips-dev, 8.0.31-alpine3.23-fips-dev

Index digest:

sha256:d1217a54f476fdfe42c65c622be4a20c652dd794da44064c56fe55d17363e377

Manifest digest:

sha256:fa75d7a49b4633b31d4578bddeaefe006c04372697ce747e640594966b56fdcc

Size

56.53 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/aspnetcore:8-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/aspnetcore:8-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/aspnetcore@sha256:0c35593ebd3f1f25c62ae8ec72777b4de1f242014c14729bee769886411e1044
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/aspnetcore@sha256:70fe5bce1df610a21a179633c7160856e2762b083ec8884def4116982301da83
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/aspnetcore@sha256:9fcd25dd4a5d45d8a0b92c7909e369b1d2b0b289243f1061d1e9fca5807e2de3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/aspnetcore@sha256:b335bbfcabb3c4eec9cb46387bad915e3566e12ec961f3bcb09dc881ff463fa7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/aspnetcore@sha256:79458e27a5140d3089cb09906e1b5439d270a0fb72fd8dfa3e2f67a109223935
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/aspnetcore@sha256:dfb9228f6cbf485632ddf91fac243165c2309ec28a7633f4a3a5017de0bbbbb3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/aspnetcore@sha256:8f8f6229eb9dd2bb944721993ec81449e2d496d188c536bcd9f7f604fb5d927f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/aspnetcore@sha256:7fd8fe2faa76714b575875ceec77ec9d0a9f5ff91c57c14212d7b7c4028e0f9b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/aspnetcore@sha256:d31f6cfb4d33c7ca352f01b5e40f46cd4726a6e79b9e2a17a1a84ef4eb327fee
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/aspnetcore@sha256:4f0ecbefb43fec6defc90f8e44cb9704708fb2a1eff89cbd0b0ea374ffc6a8d6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/aspnetcore@sha256:a3fc96d8d6fa93397d42687e335d3ec2164a9489985ec456f6749056dc8f4f1d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/aspnetcore@sha256:c51e1681c55cc217a7981ede825089148ee55a09a5e3705bf16a3d6c295dc08a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/aspnetcore@sha256:5de75d29730d0e00c564d6f338d8731c628b314ce648e68585b7476e855aee10
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/aspnetcore@sha256:a642c582f197b9ede99a73dda0989d0436169d6517786b746e3a79f1e5151f0c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/aspnetcore@sha256:3f969ba1d8949424ab2c197f6eb42536424617dedc3a233e1eee8de06f8b02d5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/aspnetcore@sha256:53a342a8bf35f4211c509de0078b19ee7167dfcab2232676ce4d243d6bc4d0e3