Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-alpine-fips, 8-alpine3.24-fips, 8.0-alpine-fips, 8.0-alpine3.24-fips, 8.0.31-alpine-fips, 8.0.31-alpine3.24-fips

Index digest:

sha256:cb4ad6e91d5fc002a13d8f7355b753502788df8fe1b623a37c102cc36995be87

Manifest digest:

sha256:d32162b144dcfbd153e18b6a6df28048f8c6e045cf12cfec68c3325395913052

Size

43.56 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:eae619bff15a1f08356393930acbbc3c2576d43b2a64a0204685c21f3c39213f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:ac27d58ecfc1fa900fcc141e2c2f93e88f5ba45d553a5f7ae17e9b6a40a0cea0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:43c0bbe25a8799c190521d87f30bfbb4bdf0b756d37493d38ae71cf4f1ca89df
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:1a48ac76fdea0cf97437ad2ac489841368ace3586ed667361d3331dbdbb10497
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:1603b7f0b6e4d455eb699685a07c37fb6c1a0a6b4d00e4cd5fc6cd2226b3d2ef
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:6637e08f0806cc2775470202be9be4f11b1e80cf1c2d1aa16d0f918c9c79c1ae
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:d7030b083356b296b4eae8e67e7d01164a22926273f1ec3bf39b18dcb59f10bb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:eebf3f3397fd53d47e9e89e442a558a797ed3c3afcb6dfbec1e65d5821b7eda8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:999a2d6431be5096de058aee3e8907e6d04c41d58152855d689aa22e7663c5eb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:4e36d35d6c10723b3eff8cb5b0abf9c2f1e75d8a4fe12e5836632e137eaebb02
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:13b2b9ac9092c24c253d0086df6d4fa6eb817e2614853d27b0598e9a6663d7c4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:f93112bbb408be1bd828943e578e83f8d2b6b72e9c9e9d9128f15526b638aa4d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:b277d3427935c12e96d92f17a16b1a20f072535fdde69a52fc49e6420d047bef
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:0acd4f0c655845fc8ac907869f4ebd9511cf0d2ca12ec8c29c80a2b828e5dade
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:e54116f884bf1127f49f02740db22df0c00a4cbb15721014b58f26fbdb1f77c9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:12aade3743265c3871d5496fddc79af59de39398f55b2b19d8dae7b37f277b6b