Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime

CIS
linux/amd64
alpine 3.23
Tags:

10-alpine3.23, 10.0-alpine3.23, 10.0.10-alpine3.23

Index digest:

sha256:0d326e54145c598b01f414d8179320f23c8b4575eced3b46264ce35ec59b2786

Manifest digest:

sha256:171c2ebd7d543f35834ddc44ea77f35af552e5cff1210e9875a4640f4e51698c

Size

44.24 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:903455dfef55b0de335f998c0b54c7a7a3f594a392302d845ac58578ac05d9f2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:aca70a3fd08358e00f0f97e4fa2b10a4149f1563686253d29a034eaaefd2c93b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:d07c121f6fc68433965d0777dc6bf49a8e79edc279dd59584c837ee5ca3af058
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:2505c2e96d1dc6bad7d59ae43c250327ec5a5ec40303d325024b5504117a8dc7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:95d5227aa460216e69bd09e70931c3ce14161433cf30abf13a9233ea9512da85
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:32b5711f16749ddf34aa4a0e67e13a0bba4d0fe0cef0dcc29e51b5c6c1465df4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:6c105b1645439def035c59399678e4bb01e30f5a1148d18564deff889f25c88d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:2feda27905720269feb5c4e8dce6377cc35e3548227e14b58f1c413c4149e270
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:a303f540e117b8267bfa8d1a24726303c0e47e695907abfccf3d34eb4bdc3488
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:5ace04f634fa52fb126fcbb372d7deb4527746d2bca6693a6520abaf627cc108
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:8e6eab5ed54d36993f6980ecb100114dd0af4e5c88798e84b4cb604b2a47d1ea
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:ff879f3b1c415df0827f51241b62b3e54b533e4c82127b3dbdded0f39ad60401
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:cc00f1200a00aaacd7ec4365a46152c2c8d531c1359073abbfc1d978c804d994
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:3a27e71d1d855a9011953d11a5307fc2a7c40c26e10296af1a1bbf5093392793