Sign inSign up
ASP.NET Core

dhi.io/aspnetcore

ASP.NET Core 10.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10-debian-fips, 10-debian13-fips, 10-fips, 10.0-debian-fips, 10.0-debian13-fips, 10.0-fips, 10.0.12-debian-fips, 10.0.12-debian13-fips, 10.0.12-fips

Index digest:

sha256:30be92f23f273aefb36e5116147786d7d088d3f4c4179a06b3a9bfb078bedbb0

Manifest digest:

sha256:215fda5e5ab8b3e50a095d78c71ea7ad543334edb8fc62d49bb2591eb75c7f41

Size

63.12 MB

Last pushed

7 days ago

Vulnerabilities

0
1
2
9
1

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/aspnetcore:10-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/aspnetcore:10-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/aspnetcore@sha256:c4b8f89a6a7cea63e410102c534e3ffcb7383b13b18d1d2c5e259bea7de12da1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/aspnetcore@sha256:71e411015c8ac81ef54b4226c65f88c8008e5271fd06c69bff1f72c6ce29e6ac
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/aspnetcore@sha256:db6e77fb1af3923648759ce3139367d1e0622b481a3d9038368568c1f8255e42
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/aspnetcore@sha256:6b4e27c08945ce0afa4a7f9c1e584919c4de81080977866f42b0b0532963dbb0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/aspnetcore@sha256:c9828fbd20663d0fe159c426ea4905f7c516ab2712f12d98b6e0ecc8c94dff3b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/aspnetcore@sha256:0d8de04ebee66c28694ec98030a549756a9214f7c70738f660e3bd9191cc26ec
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/aspnetcore@sha256:795cacbf7b8b492d6cb8c72153416908171910f4eec0e8c597b00be589d40e64
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/aspnetcore@sha256:bd0107f2d769926f4feb7029de007577897ff35c316bef37bb310bfdcefc9ea4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/aspnetcore@sha256:f4e23bc86c74c03185f95ef65ec847b203598d1f049b82a473d3798e28f3bb8f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/aspnetcore@sha256:c39ac27ab45d589c9b4d457f7c8bb6c30d6cac16d37b61d862bf8f7b7a67d57a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/aspnetcore@sha256:f43ba354076c4928fd62fc5a6245388301e7146ec795546d4639074019d2018c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/aspnetcore@sha256:c34deb8432e87108b658981093018a46bd4962b09e79a2b8820db48d62569d33
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/aspnetcore@sha256:d43544f77525bf4daadc095dbe78eeff9ac2890d63ae096c354feb3381c3f291
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/aspnetcore@sha256:9c005c4f818f0d7d14104159041e0ce53402377cc2a2823976dc8db5cd9aa4b5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/aspnetcore@sha256:009bbe5f64bd430d7321c06555b1e8381ebcb9dd518ac7aa7b6140a32e6d1325
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/aspnetcore@sha256:5eda5a4249751310db56a1a0d615e5da84d446d002de1d2b9ae9601b18b2bb33
SPDX SBOMhttps://spdx.dev/Documentdhi.io/aspnetcore@sha256:1341baaa0720b223bd63d46ba083a9c1686c34fe6165e33ce3cb51b466d2f532