Sign inSign up
ASP.NET Core

dhi.io/aspnetcore

ASP.NET Core 10.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10-debian-fips-dev, 10-debian13-fips-dev, 10-fips-dev, 10.0-debian-fips-dev, 10.0-debian13-fips-dev, 10.0-fips-dev, 10.0.12-debian-fips-dev, 10.0.12-debian13-fips-dev, 10.0.12-fips-dev

Index digest:

sha256:87a48a68035a3fb6dbc0f6d91c057eda50bcd50ea53fd3ed14eb1264f4de4b36

Manifest digest:

sha256:3d8770e50a1cb56cf810386f60a4b8cc165de49c8cdc3bf823f0073f92a88579

Size

77.22 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/aspnetcore:10-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/aspnetcore:10-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/aspnetcore@sha256:26d7ba96f67c0a5a7294e965024fe7ffd79895aa010ccfcefb5f917be248b6ad
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/aspnetcore@sha256:5619c4a7757b58de8f64a76c2d7d5c48d9d7119dd1c6d4324ed422aafd10c144
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/aspnetcore@sha256:5fd339c40cb213c3e575a4e205e86aba0b1c8d4991f8398cafe3f2aba30c884e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/aspnetcore@sha256:3278e644fd8303b73742ec8e50a96f28e8e17050b21d3160c6cbdf76199ae545
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/aspnetcore@sha256:ee6c3cd62e3fbcf0dd0bb3b4ac3da611589703971e92435e5872bea22c376ac1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/aspnetcore@sha256:cffe576a586efe840b3982fb576a7156fac2f15a69a740a2687d7327e7f566d8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/aspnetcore@sha256:7e13caca9321c3d9c10511e764f9f2be710e72d3b5247d95ef8c9e73b5dc682f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/aspnetcore@sha256:2404830f2427ec3668e3212dfff3d3b080c3a215969801dc183bf0d539785904
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/aspnetcore@sha256:85b9245a6cb2a9477d827ebea04cc550e8fb61d278ef34e465c6c6dc0a56aaac
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/aspnetcore@sha256:fc15cc880e6ee14a522f1b6a4693e4a61deb2ffd489a35dd4e9c1617d4df2453
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/aspnetcore@sha256:a627097a347c70effbf8bb326477a997ab983c2c31f914dfa32e767369b8820b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/aspnetcore@sha256:bde463a12badac33bb2f9ec005f35fec1cb9543e4e3a0ba7d2ada98eb8cd04ee
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/aspnetcore@sha256:bae632f73a9c80ae378394aeb1f38c8a06031fed2e2d8ec621b5bc148f1fef1e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/aspnetcore@sha256:4156b04c87176214398553552bba0324cb70c4a7c409c211fb54cd559f7e6f28
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/aspnetcore@sha256:61a5a82ce90e8df4b1ba2843995ce48209972aba2ca315ff33e6821e3483f35c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/aspnetcore@sha256:194118922b5ec47d0cd711287222534cb8ad1416fadaad0fe91f689951656229
SPDX SBOMhttps://spdx.dev/Documentdhi.io/aspnetcore@sha256:20afeb7cf1d6c6ab15b0406306d9327dc37480c39890630128e82033f2225e80