Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10-debian-fips, 10-debian13-fips, 10-fips, 10.0-debian-fips, 10.0-debian13-fips, 10.0-fips, 10.0.12-debian-fips, 10.0.12-debian13-fips, 10.0.12-fips

Index digest:

sha256:73200ce960282c348be59437c1b0773013dd7a6d427c0bfe366d5709101de6d7

Manifest digest:

sha256:5e0c0b3cb5614e468c4284a1ae8b351a4a12652b6c1eae70facb8bb92f65cfbd

Size

53.18 MB

Last pushed

10 hours ago

Vulnerabilities

0
1
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:7041c09f3048d11771cda0a0616701a5a0e04005accc6240a580cc3089875577
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:9bcdbb18f776811048eb77f2d34830d24a27fdb549a30a7fd5f9c108ed89fddf
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:7a9e3ad4ddfd2ff0df653184a688a4472c28c86793f71119f775686a89c9a8b2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:e1d0512a95e9a283ddc55f874a2b36ef50966a1fa64919f23375b80da9488b5b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:2c4c1b0e61cae7c52cfc9782170d1a5510abf9ec6cff0ebac2193c427d4c3e7b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:2f2f33654bcc29eec76bc38dd1d394ea4fba6c98bda3969b23437da76f59d054
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:7ce79f1a598cad59cdb17892552d406665e86358146c011d81f28ca2ef8c5066
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:af1c9b848dddf06a2386af75d15d8243d6879c992cedf8be61cee7f0546a4206
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:a4a24f78acda55126ef60774ea07bc78d8a8ce5b279aa9550d167599c1eb58ad
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:fb11104cfdaf47fab2c91c9654d4d30895ad6933c1ea31b5065137fdc9bbfc8b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:0fb4f06604343dd85c5e0bf2191a270c15f68520a5022b87afc4cb5aeb197204
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:970235810e509ded7e4022349c04ad5dcfc66572f61c41b0ed0cad102ec73f67
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:ff4c251668ce85a1c5a2f5141190004195887c3faa872e49f9e224aa11eaf098
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:8b7a9c4c33db9d386b350cef4bab66673365b1dba2b5e2b556ba78b5c141d3e8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:6aea3e8e51ab114871da64ac40ba573c5d1d5e6c03f9642415544bfa22c3ddae
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:78b0a531dea1a807141bb3af8d2067960f5fd3488158c9b7a3556499e2011c33
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:39b9490d6d33b5bc7a6b590702e45d0b373d1c256d1fbe08f3884585198330b6