Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime

CIS
linux/amd64
debian 13
Tags:

10, 10-debian, 10-debian13, 10.0, 10.0-debian, 10.0-debian13, 10.0.12, 10.0.12-debian, 10.0.12-debian13

Index digest:

sha256:c1690a8548e689c0a817f2492705fc9a9b318c65851afa96b349aa0c5631d62e

Manifest digest:

sha256:b96507659d21df083113d6a35cdd8d040cd089fbccfdbebceaaabdb452733b54

Size

52.41 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:99fc84bb6d16b8a94b175981bfdbf518c5e8b92c49e980e28b5e0a09fa119990
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:96644758c71de79a48f0d273f2b8d431251a0cf526815b65bb2f2831d558af8a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:1d389d3a32e0cc90643ee9711c9afee3641de212b3bc7ecdee5ec3c3df00877b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:3429263228b832b583dcf7a674880c7df174a6552cd4e09d44a60b745384bca6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:d08c69476c43a89cf46c928ea9f738b605e5e37cd35ec674d883b7a73e2bc387
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:22a4f0eaa33721d7ba82ea98b551581cb55052c96b53bc9593edf954694609e0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:78df025e08abe3dcfdc43b5e838d87ac681d1e8053eb0a7108db210afd991e44
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:3c6661a8d4ed44bfcf2d5d0c8ad4e5ed5662142cb81657e09a7611de4708b150
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:0cd7ade65bb0cec62bce848c2f3238e4e3e39e10a85cfff9c124339dd45e1d53
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:a95efb653dcf3a3a87197a6e2080146f66a8d347f7382dfcf868d599ab5fd936
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:565cd31098c898a1dd2729ec446097d3524c8ee35abfb0ddabb93d2270a9f8f7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:6b12f4b51db2cc63b358862ec5508fa5533bb4a7dc4f5a7c0ba3a314412e5711
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:65b515dfb95e909c0a7c08d7e33acd773843d11365e618c4e9a25f5759f86968
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:00e06ae1b108e71566badbf14752c565289a38bcace75d2b3a3bd1776c4fb16f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:9d2520501026acf6cea69799c9495dc09b3b5ff2660359838fefbff8937368a0