Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x SDK

CIS
linux/amd64
debian 13
Tags:

10-sdk, 10-sdk-debian, 10-sdk-debian13, 10.0-sdk, 10.0-sdk-debian, 10.0-sdk-debian13, 10.0.401-sdk, 10.0.401-sdk-debian, 10.0.401-sdk-debian13

Index digest:

sha256:29ecd5181663c89a008b20d554cd17ba7aecd642678957ef060f9bbac646d089

Manifest digest:

sha256:4001190549ef3bc229791d9eec8da282d0b2c868dbfb6251ca343a5b242b92ea

Size

242.77 MB

Last pushed

5 hours ago

Vulnerabilities

0
1
1
1
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:5fcf9e35989661d8be44d99dba7ffdc918fd98b3063d0de384712805ee1f6b8c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:f1f05d599a23164df874a75c52696aa5873643a30be70f6ffd83e80b0ed47a40
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:b200977dd04476046c0df508127b8dc064cb0a9147ec37a4011d47e527d3e464
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:af7496099d87a8e276f2db1f5121725a023e7b1b34f7f7aaaa3429ac018c947f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:8068d9277b80aa5c6b4f22a260dcae2e0e2804aa0f8b190bbdc393559d475c30
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:7172adfae07388a27eddf09e169e22ed2ec0aefa21d093a79942a5c5c1a0f7f6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:ea1a56f772329ad6fbcff0918d76e3b1a7f8c601e940a4168b75c05ce986b0aa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:bc0f5bf3bd340d1ea6ae9793bf338f7d534c752bba6cee62ea4457a0f7ebeb8f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:63f340732b53baac22d526bbea33c5408ec395a96284246d3bc7b2c596822276
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:748c17a1077f26aff6ad79ebdf1e472813973427c8a83f282a4ac6f673821ec4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:444e636fbefbab8252a01e14e0d24423f5ad38368ab7b18bd218f28c8ded03ce
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:f22517324fd6a910354c01b2ac46ee55421b75aff1390a83d62d448181a97887
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:e14feb8faef478ae0bba2907bbad625befdf92ca4723a69619e0fd9f6d1d9576
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:f4d22354a6aaf36a860d62c3473a4bee35bc23c6215c38a81b214ead19f6dbfe
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:cd81add3bdf9e22fdc255e06c0e5b80c0bbc70e384199c756dbe9250ec67fc07