Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime

CIS
linux/amd64
debian 13
Tags:

10, 10-debian, 10-debian13, 10.0, 10.0-debian, 10.0-debian13, 10.0.12, 10.0.12-debian, 10.0.12-debian13

Index digest:

sha256:b7a3a45a4c739ace774bd1b5339b8531405174ad30349e93cdf546433ee9794e

Manifest digest:

sha256:94784f7779e7535673ccec0881bd4a0fa2ca56300107def4b20d67757f61f5f0

Size

52.41 MB

Last pushed

9 hours ago

Vulnerabilities

0
1
1
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:f5b0296e64f0631fbd6c6cada7d16b05945ac9a21a17f1f1c1ceacc13dbfb7ef
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:321b06b7a08c05aadc0c60ae940c15e6bf47b86c0425765bb476d7388bd7691d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:ecd682b9ba492e4c44d811cbff988778dd787e596c3f0b50430b99b7ba079239
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:a20da6fc562c368f5cc0a74c2ff1a5bd0c7321aea450010335d80fab9ef6d3a6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:4fa893a86521c5803fdbf9126dec3e02227eb2ccd3108e7c546af645faca49fc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:bf44d2e22c0928289f03d35a105d81647471e96e452fa3975f7b3fa12a1a15c0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:5f7884aa5b18f4172a3ef0ebe30d99ef9a50aeff4fba069e67bfd1dc1dfb0ff2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:4cc48c4e3e354d8080fe5ad6a92994d8ae6eb7d1943ea395b09044ee9e8ca3ee
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:548b7aea68b1b539291d11783c64896ca05ad0ad52faf94a246871e3ce3671dc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:68c41ce6a17fbfd8de9796cac04c4d8a6e26178b1f5b9e9405c058ca0db5b552
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:4c252fa29c57300203b045ef8e891e96476daf56485296c0988961720443257b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:4914115eec4205a9a9add1c490dec8b59027a05b26043d146cf14fd73e40bd61
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:f7e85a63bad3e6579403c57a8c26c78e4c7ef335bfbfc8e283a042110e09bd8b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:2474b52e2ca652faddb9e3620f270d9858f32a41e7db6579bbbd4790b19a8994
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:2f9098dcb4abf42e5faee0f80e3ba838dfa1d9f331cd85f1e2edbac00ebac6d3