Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x SDK

CIS
linux/amd64
alpine 3.23
Tags:

10-sdk-alpine3.23, 10.0-sdk-alpine3.23, 10.0.110-sdk-alpine3.23

Index digest:

sha256:e95b805a6ba4e6a926f7b252db2b1377c7023fe15f245c0a6686b400bc64fd35

Manifest digest:

sha256:0bb86ab6485e993f923101de85f37b27f045645e6a2d003f7c95a4860d4a9e2f

Size

218.95 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-sdk-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-sdk-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:8d263a954e80ca893bfc8dcaf033ebc6aa662fe8de9a18d67b671f89e3a48311
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:cca53e02cb394d7c70a78c4f1622d6aa39b4e26d5ebb5edc2805841ee0f58151
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:f11bce1216b1df397af7d91e8d43b9aadb626a49b10563d57f9e73a2393ba4d4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:5c6155f58c0ace44006f8bfffe5c1d0e8a79da4234eef23d0be342250b13c31e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:178377f984fc2b95d058cc3e43a48596ccfad71f9adb10971e6b2fca68ad9cd2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:119566a5d82ccf93215c7097b7b384ebfc764e7dea9ebf0586e1e23844a857d0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:0bf6cc5252e3b92599dcc9eef2b8df05591f1eb9fd430a922228fb8d40777abc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:5fbcc29c7572e6d37881927225d645cb313ac7c7d3004ba03023fc2cce02de38
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:faf7dc3934ee0cba62d0c8f7d616e3b736cb848704e176bd95588413534c9a20
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:90ba715f4f431a0aaa253be19fe7a5c76a44d62edeb85522029f0c06d521beee
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:8ab3495d5378580d149c5d2525f90d3666161601eca04c3996970a94b66dcb22
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:2e947e2a89454856526c8ac18a063748ea26ae4650c4974a48f626c877ba6d24
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:40f99aebf2087f605e4f7576dc3312936726493c4574dc711702e8d00cdb5881
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:eb3c3cfac75e48b07809b687895893947be366c7a98fa08610fa89c8a1535129