Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10-debian-fips, 10-debian13-fips, 10-fips, 10.0-debian-fips, 10.0-debian13-fips, 10.0-fips, 10.0.12-debian-fips, 10.0.12-debian13-fips, 10.0.12-fips

Index digest:

sha256:010e490efda6b41da25d0c01e027e9f5ccc75e34355774f7b3973f0432e050a9

Manifest digest:

sha256:79a08d1e1c9459f8e10a821b753398b4876eaa84e23927143ba7f3b8c98210e7

Size

53.18 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:7302d105af01b823a8f2d88b907fc0122b22dd4adf1fd76e5607278cb62e879f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:90083da0d586641fc7a0a8c59f86e086a00f24dd37964274896d0a7fd9cd824a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:f6a48dc4e32077ace04320f175f4dd601adaf966d39e4bf6d8efc2c4e15d2704
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:b7bf5cf51085986d00e09c9c30f73b42efaf34c6abe44201af497af07877d0bb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:a93ef44decff0c3ce7041235c31f209691b54c3e4ec930927d03070e5b1eb6b4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:dd218a0b0e49962ee937a87d08486cda4a4fc643526e75ce38acb5aaff227b7e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:585a8e972a160310b95126f4c165ca8f73f49236f06ac9f2b5621b9a9fa28dea
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:acc71b42e8da66d065e53c27898229e724288f2cffa6b7f702e1d43cb9fd46c5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:66a6df0c9d58bde2059c73b8e074838d06ab515248d5e80d73b6e2a3a79285af
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:a33631d4088d3237b5a840a3504dd1abc458635461c97a24955684635430f20d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:352c0e75c64040a623ccc0c5df575f259bafa4f8e9b02f7951022b1dc986be0a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:430e268de8bc59fb0657c40715fb43d5ec851791eee463ee2ac74c335776287a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:45b83f7f46f0f6398e8aa77789adc9130a219a321ea1e0d17715a74e04641f72
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:1cc3a4b47cbca0e6f6d0d6afcf01f59ca769d80908da93b7adf5650433275b3f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:6855bc2482574424e57bc3d8788d146b1fed3d32c92e8611ea453c324715987b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:d1ea6e0f581580efc73e4ab5016636994b294745f837b7ac3944e41d5f368f4e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:833f38466d700ddd390c0807904149e4ab35c39156282906f31ffb1d93b1aded