Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x SDK

CIS
linux/amd64
alpine 3.23
Tags:

10-sdk-alpine3.23, 10.0-sdk-alpine3.23, 10.0.110-sdk-alpine3.23

Index digest:

sha256:03e96b074274fe80d5af75273597230e2bf91f7afd79bec512a549dff0eedd37

Manifest digest:

sha256:cd99ac7629999ca3428e6265e45ef8e2f18b4897135f4268c9402a452fc7a3dd

Size

218.95 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-sdk-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-sdk-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:52460dd27567df14b475cbe6bda134c871fc0c21fd74d63a809183699cb2ac71
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:7ed93b0f0b2375b33ee27558aca99178bd8db72f25a4a8072788c37b11f9702b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:3f3ecfe14bf5ecb3b224643c90928ba91e6cb5d0109a8aa49ea075a8f7c981df
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:f8f890e0f5245d75c7c6e6b4083aa4c027935073ae31e328b56d2af4a033d13c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:b7a24260ea47c5ccc0231a9198dc8ca33b5f7005f14b975423faef9199e50b23
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:03075c11a916274df423f99f752edb3e5d92b373d8e2f6620ce54d66667ae4b7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:46a09ca0a2125c9cd9f9f8a5e42d1fb1c3d218544e35f01a81af50f87d6998cd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:4bfc31d85e214d4bdd94e31d420fa83541c4b33aeda7b868fbe5f68b9f9a84b1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:6943f74ff78058d628245fc4a0c9260cce3c6a8bb4f90c6a6b0f0c9b287be59c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:487011bf4dc8a81c1858edc6b0a3d2d81f0ab4211e3a7075fecfa73142903dae
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:8b56a83dab05a0a8d6d6262fadf172e188c90da5ba539af886fb28ebb95f5640
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:39469c6077cdf6025ff5a7fb22dfdfdefe8a0797c0e540c74336cab2ca57e49f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:a2a703a0a46f36d4e9d7e32c83c4c1dec3d8cb3ac2d2319ea562e72b955a87d2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:72fbc4e5122775f8270b52a5be4a78eada4ab1c6890a4677e7fb51a0f101e5af