Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x SDK

CIS
linux/amd64
alpine 3.24
Tags:

10-sdk-alpine, 10-sdk-alpine3.24, 10.0-sdk-alpine, 10.0-sdk-alpine3.24, 10.0.303-sdk-alpine, 10.0.303-sdk-alpine3.24

Index digest:

sha256:940b80626b2d68dc045c1eab65f1285b152c3e90002ae618f61a862c5f5b9774

Manifest digest:

sha256:8744ad8b1ae67788d994ae683f6d1c1e4b8679deb0d3e3792e65b73a0034810e

Size

217.20 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-sdk-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-sdk-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:7afed3d103e2a5ece51fac54e09f6dde369a3bc5158dc9037daf98407ca5474c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:11c1be8460ddd8f0106219e68ad8c55c5e939bdae8228b4598457dc13fc4a57f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:9d93e79ba78737fd70d8360a81cdb881ba6a9d5ebe75a94cdbb98892485cf818
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:d2b83c0b6252c6b69b036fcf060c380928539417d354193dfc788b2c9b8c7f16
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:c26fd973402c6886744128b3bbc48bf17cbd5df36bbe04da4a1a95155cd5d3bb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:e6628ca0fa3a493765bdd47ec6a335ff518b16c09ab91b67f4b97fcb1920d9df
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:a030ec7ef48110965a56c7b18da3d63b4f3b5bcc6ebdbb4e7d012652706e9d14
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:e79f913f807723d6384debd9c682877c0371181e1f3870b31d6f7c315818bfbd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:4cca96adb14342b553d1d5222595f54edbb3d1baae6fa29581dfd8814cfac44a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:2736f6d13d41abe3bbcf957b27ffcc72f376e92b628442ecfee15938e42a6b53
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:ecc4392239536e555a50a1d130153248fd4b366b33c3cee7e920d822fdd24260
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:3db06c844fbd4347caac23721a126c6c481b18ae39cdc9d397fc6613cce8c7f1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:f93098d01732d015af60c9166decad726e21b99906aa7576a4e895559ef914d6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:57b55d4c6e455aaf43d40cb194cdb2ee5bc469b0c59a2726a6275890bec8b43a