Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime

CIS
linux/amd64
alpine 3.24
Tags:

10-alpine, 10-alpine3.24, 10.0-alpine, 10.0-alpine3.24, 10.0.12-alpine, 10.0.12-alpine3.24

Index digest:

sha256:e4e5c49e7bc86b926407c9922d06faf3e95cb30f281f9559d4e3d3e22d3b0bf8

Manifest digest:

sha256:ebfe115b0a6252977e9e8761e536f22055c19a5da73ef6038059705de750aa34

Size

44.61 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:56d3ceb2137d25bde3794ac664b7be1c887eac02b45a36ec45ce979544f06c32
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:230412d61c1f59ef2f7d7888cde843d90fed436aecf63cd17b8aae1849a15847
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:575d794b97bd95c2bcfb9a8cfa19153ba7f6c391f61aeb28ba7280b2850634b1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:e98901424e527ac8aab58a6f186193b1504645c6604f1e4100cb4fa002b813d0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:ce0deb5db04e339fbde047e518d6486fc66276d25def2dd6d7914adf21364c21
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:84846947a446f59cbcfa952851491412d180b183d22cd8cec2a0c64e3ba6b93e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:963c3e36af4f9f9d2b8127ed1bd2f01a7832c659cad1abd2ab5cbd696938e6de
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:804b6f2fbb58aa49c5ffed49578f36fa3e5342935ff4e0a7ed7ec6568030b473
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:5290207b92d15edb5899e1786677c21a18f709e11f9ca08e465bfb2eca70aeda
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:fe52f7dc89c0c52ee98674ed62faec3b289f63034b54322ebfd7bd46e3e3f071
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:3ea5fa64dee1e336cb3de1ff0d185e1e6c3e241c3afdb55cc02a72fec44ba3b7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:9e460bd269dcf6a18c922da3bca15a993ff73776f95e77e5770915fe74b221c5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:d9305711f9295ffccd4f597725d7114629902c6ed5a4035d317b315ef6aa4b2a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:0c3b27a13fc591e713f506dc5ca371b35e9704128ef6b236f62173952f6dc3a9