Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x SDK

CIS
linux/amd64
alpine 3.24
Tags:

10-sdk-alpine, 10-sdk-alpine3.24, 10.0-sdk-alpine, 10.0-sdk-alpine3.24, 10.0.303-sdk-alpine, 10.0.303-sdk-alpine3.24

Index digest:

sha256:ee5838fb4bca7bc1ea87e2dbffeaf2d36a6acf34acdb1dcdcf550e0c5bfff9fd

Manifest digest:

sha256:aefc0543682bc2a95ceefbde4de702175ceef6ddcf5fcb085fcaa83b7895bc15

Size

217.20 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-sdk-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-sdk-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:4d621dee87a768cb7bc99b06e6ddb4f44709cbfcbb1e31fef4327db42ea818d6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:48e541b81242f542b0bb5655654a74b43174b6fc694143df87f3dc6baab95ce1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:9b0bf4a929dc2d75647ab52a0734827e41546d40e820ec98a933f7c759c0fe66
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:3cd822d750067ca063f7ecfdcb85318b7b29485119bb6b8052b4b3b9295f3126
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:1f1f76220197b2bf6284474e44fa3e6dda5e9df6988de0b415d714453243404b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:fa33566fa6c7ef1d641834c74b58101693e33ce0c04ba2121a7488112087df81
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:b01ade2404d1d6b481bd2188f3fa9aa4db113907dcf2714664414ca772e2f839
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:7f0904f86c73ec1a71609b7ea371b7ed1d311d447b5a2bea6cc2e819ca8bdccc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:7ea2061ea686656c6e2496a4c36fd4c6123e8dc9b8b6a6cbfd95713d56d107f2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:38be5bc139b6e7e684cd321aec803bf9334f2424d947215214e148b577583e88
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:b9231374aab4f22b3fc1766cedeb739cc6a1abb293ea713b8c139c2bb08ff45b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:7271d483380ebeb40a3f25d4fe45677c7593421fbcbc37d7ffd708478335549c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:aae0cd05945b46a6c6ca7322692a4e1d1ca726055ff44e088d87939093718fc0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:1fdc4f19894f4cc5ed96fdd2f921e6b93f8afbde3cf99dc7ef4d24096113e33b