Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime

CIS
linux/amd64
debian 13
Tags:

10, 10-debian, 10-debian13, 10.0, 10.0-debian, 10.0-debian13, 10.0.12, 10.0.12-debian, 10.0.12-debian13

Index digest:

sha256:ea475c121cac6a60e18e018c457a330a933527d0ad9d77c9a69ac82702eb6edf

Manifest digest:

sha256:6ee0148eb571dabe74554b5bf94e23a22e4760afd683aa5d4314bd75ae3b2e4d

Size

52.41 MB

Last pushed

7 hours ago

Vulnerabilities

0
1
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:781fdb2269d23e6823a45e8f624ce78650cb03a5ae86f61938001569b67d2dbe
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:435cacdfd548341e29ea985b70172e847364741738c289949942707bc859d297
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:2a313d9b46233ecfb7ba630e58e75fbda859d201f506fc1eec7587fb2b1f9890
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:dea6796afd4eda16e460c7d14168f45eea00e54d274087d2c4efffbbbf2fc555
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:ecaece6853284a3c1666dbb097a7b59ce7e5681a488152ba0a2bd2b712067c09
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:eb454a0fc827e25106b9ea526cfe122cf0578d3e0d286c6a268229d665a64d42
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:ddbe0b55ca7ac2b566f6e2812736eedb8d393ad365911c42d1b3ed20e6bdbdba
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:9b6930968f458495263fc11936573753f97da993111f86f4d051dd120d041cf4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:015a9c0b4552a46ceccb3f54bee1b7a78695b5733b193a86186996377560b9f1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:a85d577bf607dc9b137a2e63804d84aa1749204c4cc312280557677227c46e58
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:f059a72ea364fd71dca128c31cb0bae4cad7eb0d8dd34e1fb855d49dabb6b889
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:3d6b25ca5df9db2d24d40fbf6ca11d6c4e0c5e450ee473ba21a7afaba651604b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:311bc02936399387d8f329f3beb734925ce4aa5be3346e9e37bc8bc0bc367097
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:f756ba12efe4c3c7e8bf76b0b363bbf64c00308673d23ac555ff0fe76e33986e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:be771acefa5148e01a1f341752122aecee0a7b78bbfd500bab53208376b7ba9e