Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x SDK

CIS
linux/amd64
debian 13
Tags:

10-sdk, 10-sdk-debian, 10-sdk-debian13, 10.0-sdk, 10.0-sdk-debian, 10.0-sdk-debian13, 10.0.401-sdk, 10.0.401-sdk-debian, 10.0.401-sdk-debian13

Index digest:

sha256:9a47ab2a2a3d5dcc3d6281037cce87af8790e651c3f71e17ef335171d265abe9

Manifest digest:

sha256:2a327d50013ba6d66b22fac20f57a3795fd0f218407ffb8c11f20e53aac5e213

Size

242.76 MB

Last pushed

2 days ago

Vulnerabilities

0
1
1
1
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:723e26fa626b89e5d4a4199bce4f357c480d4d4fae8d36fa4313806b9a545068
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:e82a7af9a3de0603cd739de98f26eec0a8bbe74411da5c72050bb9ff42d5503f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:ea0aadd712b1c62b82951b5dbfa65014371699752e32ee3418075c32f5be269b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:7498a3b349eceb9de1ac9ea0a62984ce1ab5843c40933ec1fc668a6252dcfbb1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:2ba578f6087be2df963b00fb1aca62ee04d90de9fcff60bd1b16cc1f02979216
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:0f7222708624defd60d4293c83b3b41fe628c1b7f4b8db9bb10e959b586a3c63
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:2e4b2ffb1741c26520da6cf1c176e5f85f2bd5a14c59b26cb36a54c0fbf0a41d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:f60ee51d0687a73a064f419198594f240a277b7345899e9c45105c7ab9152e4b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:24bcef81b02a3a5f01e490fdaf96c7d456ecd33b86ebcc69993460ae76e5cffd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:8b7c3221034aac236813da4857733c33e9d0b0adbf68ebbd8486cba787ffb168
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:0b6b1dd206a0a3e8ae182e27d0ed4b445f137abc85a89f60dc0cbbff22b0a360
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:aea088eec32470f3dd337245689ee67e9407e310b6be16fa1bf73d04df74e726
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:7d2f1ffedb6794f789527f300af8f4367a1dd29ba0cbca8d9be04404ebee76fd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:4484fbe0726cd25e6537f5a6b0b30376a1a9c25e4fa6d1363e45b01768955002
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:0261520bc7c14c9251a9ace64e41c09fde53dfbd4110491b7ea4738c13727bb4