Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime

CIS
linux/amd64
debian 13
Tags:

10, 10-debian, 10-debian13, 10.0, 10.0-debian, 10.0-debian13, 10.0.12, 10.0.12-debian, 10.0.12-debian13

Index digest:

sha256:122e470ed224df82b50fabfcb8314c2aee9e22c03d69b5df7f211f517a1b2b2e

Manifest digest:

sha256:db0ca382fa57ad51de0ab4a29c416a686a9c84b7240746aba833a04e94ba22df

Size

52.41 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:180a52ad388fbe0b2cf1c8c582b8b4a5290f4339c24f6284da06b83b1ecbccc5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:689dd580b102157abd50059f995cb2d9321266f8a361c75363829ede2b6ba3aa
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:ebb517b08d356c71cc936586ffa50f2114a00ab26b5f37ce7bcb943aff036b0e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:f14b337f78561eb2ad4c9d0d82194cd28c7d9019150aa68468c2d582a290f694
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:3563d8b7147b6bc04ee3112c6923b03ad47653f31735389765f52add2985113e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:956cc6c342a07a0da56fa2fc6c90f31d57e6de5f92c127b087ebfd3afc25005b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:c9dc0879b7fc67bf4087bf6d3ac48c8f9096abc7007d3c8c4a72fdfa2016cbf3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:1d069d849f4ef704fe2369d41512bb54fb39b28c63aead2d450af91102da29d6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:eaa52a54a56c35f1722a285d60ba809db97c37c2e7758ba81f5b06ea18d1387a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:f2d2425479e0a17ea0e3e7e54b03488f2022d2bfc1fe4b8318b0683c9f79b79b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:56093b94f51a4912e1606c00588461b6cd0c02512041427d806ff99fc5bedf6d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:98934cf426739a87c423d82bd54f56efea9fc36acd36223f16180e4a69bbb1f3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:9325a39c5604d3665896746de246f94712fa2c95f5c58bc175c1a9a0c868b3b0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:bbc4a74590a9aedca377a4ef35d67291a940f75a1ab508f649f93d5ac5f0aef2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:cdb127641a34540e9a85a71fcbc9143a0882e22c17413ce3e79bc43744e4282b