Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

9-alpine-fips, 9-alpine3.24-fips, 9.0-alpine-fips, 9.0-alpine3.24-fips, 9.0.20-alpine-fips, 9.0.20-alpine3.24-fips

Index digest:

sha256:d218f8787a5eae9da11d331b197ef3623b8373159acacb129e4686d5991e4421

Manifest digest:

sha256:e3a356a2f6e3ac4b4fcd1c42d530a7abac2d6eefd70540af833f865af8b7e99b

Size

45.02 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:9406e1530d2d77939bf41ed89e972766fa02bb994fc429a1a13ceba24c16892a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:c39a75f3379cd7b99e5ceed1387c3f4915038663faed13fc197c477205f7c3ad
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:c90b96002afe5a2c7e451ab9c9f661ecd1cd64f138a65955f4a51ddaa450a062
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:2106fb0413e4f8e3fbb15195579792ab06d66c08e6abfb3b9a37fe2916ba62dc
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:eaabdec18aae861ae0a191d2aa396c0228633251105f1f9e3fb79bf8ceccc76d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:c3428498ba9e2a4dd943490bee544f3bd075281985a03c338f6d6d673ee136af
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:96c907a087457ff3c3d12bcec6bf47789cb212cb4cc3e06b0f7ad5892566eea3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:e4ef59f6c048057979419f623a7f813b7a54d4566ab11754bb4c8c47eca6bbe9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:859977750061d4c1e28e1d39362c319e06c6588134e0263f61681f1fd0fba429
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:b14057cbd13c6c415832b4d970be499a7a04a01d94c5df4b752d529f081d3f7b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:fe27f0c2a2f71b962f106ada7fe8cffe45208beb5bd2393b9b12389414d9063c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:29705d43a68815bb8784c699cb848305172d578add58e84b53a2dcd2717cb774
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:40ab061e570519f747202d549e6b6bed64b1252efd32eb470cea73f61d5a8872
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:1c66ec5a5ddc0ddf6be624094434dedac5ca49fd367a8dc89089e44ca0bdbd18
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:aacd3d691d52093051b6178c5a92ba42ac243f4cbd23332c4840ba28a77e30b8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:d17a316dc3dc8c9e32bc798cb7e3fdb0a664e60fba1f76c0a9f5904866d09a3e