Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

10-alpine-fips, 10-alpine3.24-fips, 10.0-alpine-fips, 10.0-alpine3.24-fips, 10.0.12-alpine-fips, 10.0.12-alpine3.24-fips

Index digest:

sha256:437d35414ba2710c42189dbf20ab806330a917d2934f492372d9816a3cb15790

Manifest digest:

sha256:982cc28abe08ffcbf78760bb49b87f4195671929db6f728062bd7997f6eccdaf

Size

45.76 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:896b99259a7762ad7784959c3ece8a4780f424f3320e99bb319c11b39b1991b2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:92a61c9d03bf17233183dc0224aecdfa0eebcaa2dde284c3a951a4d5d39cf3db
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:a9e9262f3e1c51f16027d01d102799f2a64a3f6f83f56408498a90347239c195
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:0c190d850f292d4734a436c3aa93c3c96dad85072f707041f21a8db8b45321d5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:a2c5fcf4ffa847755593d4ce821c8610ec0d0a3ebf5cfe5cb50e0cdf64a6d6e4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:fefb074255dbe88063b51da4db9ed06fb0ce3e43f91d391ade9ea92e9ad90dd4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:ef2b527491d2b9a6ed3235ca678847dd704c9434529b1f0219d87df8d05b279a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:3980056c1aede7d96dda27978d87d0457a118ee527c2eb77972ca544d7241a12
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:42b4e9ec98e9413fcf6938e013c660a7d493469c449bf43469da15fb7eaf836a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:7c476678cb7343245daedb0bfb6626a3049436c0c32c9ede0808e364545aa4b5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:ecb6bc357ea5582d27bcbaa9396ed37deeddef0238ccec9337466f74ef30f3f6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:d5f2e419c91435bed876e011a4d07b726112551d05572b302b4d7a42f8196931
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:75c4377dceb3b5c35c8b161b3dca083cb918dfecf9b3d7ef52e009fcbbc9683e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:3f239a3f337a9e224333748ecf5681851a5a768d38a55e3908075e9b9a1a645d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:e29a9a8fe00fce1f43995c55d023f07130d23e1a6377a5d0f4f1423a6f1f55e5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:3aab5db8fd37a474b240af0b0cf4abedfd7a48948b134df60c1c8ef13edbded5