Sign inSign up
ASP.NET Core

dhi.io/aspnetcore

ASP.NET Core 10.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10-debian-fips-dev, 10-debian13-fips-dev, 10-fips-dev, 10.0-debian-fips-dev, 10.0-debian13-fips-dev, 10.0-fips-dev, 10.0.12-debian-fips-dev, 10.0.12-debian13-fips-dev, 10.0.12-fips-dev

Index digest:

sha256:f72add7582f50af508f642ff9eee42fb636143246f2e64b08ddb6d564097848f

Manifest digest:

sha256:7bd454d1d8d7ede3ae0b47246836cc0c8c6e3ecf90cf47d8941fc6e2f0adca6d

Size

77.22 MB

Last pushed

9 hours ago

Vulnerabilities

0
1
2
10
1

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/aspnetcore:10-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/aspnetcore:10-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/aspnetcore@sha256:d12678de870acac54f12ba03b9f05b53b3738eb92a0287a9fc84be9a64110b25
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/aspnetcore@sha256:c7d85d2cb82d9ee3ebdd060a1734e649473b466f1081737834d878e99d5e39f8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/aspnetcore@sha256:60d7eadb4b8f2b48801f3b06e3d6e3d26b813040372d540ac55abaa76aa3b40d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/aspnetcore@sha256:a9cee7ad75cb9acbac1951ee5d9c3957bd2b38958856cd7e19627e29bb8ded10
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/aspnetcore@sha256:a78d2e595a0fd3d4b41cbc94a492b68222f3f90a9a4ba270a41d265bb5f73755
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/aspnetcore@sha256:ba2cb6183d4af4dea0d797ba5212d762f84895a1bc57fe112efc5715bc5d2879
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/aspnetcore@sha256:8ff969fd2c19dc9d2c2161c995e9055c9a7b3047c147f123996b02e282635177
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/aspnetcore@sha256:25d1c4bc5d0f85d76b822d311f175901c8df5105b2759165ca4909ed9a3a417c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/aspnetcore@sha256:440afc5849d4f812e85d5a93cbf0f1efaac12c080f75cd80254437dbd888c9ba
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/aspnetcore@sha256:6e5aa129a848e53be24b21c26d0e8a36f4f71341a55632f913e2904fa299392f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/aspnetcore@sha256:b10227f97e9f987ed986ee9310f9ef5ec053d48b1cebb799a5401c6fff505e52
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/aspnetcore@sha256:f18cefe59d0bd32a17f29c36f512c513da3785c0d1c5be885b9a3d212a258c2b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/aspnetcore@sha256:b8d23f618472c81450c5f45819d1d753ad0932593adb632c88fd19a2ef2d717c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/aspnetcore@sha256:36c37035ad2bc9af3f6c72605ff0bf863782985ea27b7584ab83ddf84f3e48db
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/aspnetcore@sha256:fcfa6a1fb1f6bf824d0a61e004fccee24ff97242cff980281725e50a8495bfb9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/aspnetcore@sha256:ff18806f9c0f42602d636c76c25cf19f2368b0ea867de66b52aa034deaa0c3dd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/aspnetcore@sha256:18e7130f18c0de94bb4878bf825825ed36ce7fb14c98745edcb946b176c984f5