Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x SDK

CIS
linux/amd64
alpine 3.23
Tags:

10-sdk-alpine3.23, 10.0-sdk-alpine3.23, 10.0.110-sdk-alpine3.23

Index digest:

sha256:6af86ca453876f67e39c47aa39fd171ee715fa2fb7bdf67061527be109901aa0

Manifest digest:

sha256:748cba7aa281a7b8fe4a0d3e924de8a5329bbd75a5e3d67de3b4eb4af83aff5f

Size

218.95 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-sdk-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-sdk-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:700813f859ab9297614d32d824dcde715d027a4a205d13d209c5a3e0f7c46158
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:21fe61bac8baab504bacec7372a3a94f321dd847d30b5144682935a1c77b00fb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:b4dc7affa2b1b216e0ed3eb5fd0d5500c814cba228340ac2357620373fe9826c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:aa47dc53392022ce6ee0f9e364a2d4606224a9d14638af4f2beb3cc45328fdd2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:728de3d95851851f5f3e9e578c49bb764d85969df6f486e15883e177481d79c5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:d8b23fa58b4386001159e6b862aff21afea0cb4f4a4dcab99069f827dcade03c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:58e91ac287307c0fbaac19ecab66db1d1fd55f0dde8bd82741e0d38b3f58a571
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:2865a3de333ab4002ff73cd2b33deaf96963ac87e62fa5f34e217f876c6bb85f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:116cb367aebea80fce9d8d11829b6e0cf1b6e0a3dc568e12310d596e7dde246e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:ac1d95be131b7b19c55998745fad39ab4d777f56cf35b0c94437f057ce787e8b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:48f02cc4d3d27bf81c354e6e7d8f41376a07a9444d8ba08a5bc712ffccafb3b2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:63e7ae9107516ada797bf7c57dca9aafade5be2052b65ed1e12d43a7a94d2552
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:069a101c3bd1104a6c3c14d55b8cd021c16a49794f008f0f3bcd82510b6d77f1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:0ee3974a315a22b1371ecf5eef1cdcd0f589643fea986aace63a5bb0ffe783ec