Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime

CIS
linux/amd64
alpine 3.23
Tags:

10-alpine3.23, 10.0-alpine3.23, 10.0.10-alpine3.23

Index digest:

sha256:c56b3192042851d7b0f4b333a11b416bf3cfc95a40e03b1651289be9ac6e08db

Manifest digest:

sha256:fd811206cf2828efeaac3d9eb8755fcd5497f412ca3f40e27d33e1077dafd1a6

Size

44.24 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:cb8830e499b697c02489744a46d8e1d68e5de776b6731c52fc503363c4653373
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:0d8362db70384f9510e9712f1c1297ea8abedd918cc1a1e20e7ea8ad41d6eb29
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:fa061a1e9d230dfa757c2dd8a936e767b3fbc1a5926f82729450ee64743e9109
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:bb8d884a9dc1c0b96ef86d66fec1da3aa67b3292c13bce4be5b40e65fcbd7720
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:c08a37878f9a6c6fa2bebe9a9bae53b7ca5504848898cde7e0639e35f634d0ef
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:3931cc74f1224345b4398e453bf59a5c5c9046dd0a3881e9fff3d276ef21ed62
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:6b3633dca3ae00808239e8d9e5b9c1e06e04a3561ee6ccdab7531f9160f6c611
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:3443fca23dc4ab9cd005c86f9ede59c526e56fb4289fcdf048df8541adee3873
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:b5c8bca7790675de28a065797ce282446861403d06cabb1bcb301c7442baf1c3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:2404a8c311caf5537640b9457c9fbfd900a50111280412b4a405a047ee18c07d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:cc43c95c10bfff2bed3bcef404c66b3f65b4184bcbb64f7efe8a2de311bdbfb7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:c386b207651ce91adc0e99f782652bf9cb93d2108483c0f23f9d0361e0ff989b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:24492b0e78c7e5fff87c602e7e711a31d3509ff69906793af2343997aa769506
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:131cb582df407ca14f7e22e849585734c04a43e72f7b8d9182f266642fe0ce5e