Sign inSign up
ASP.NET Core

dhi.io/aspnetcore

ASP.NET Core 9.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

9-debian-fips, 9-debian13-fips, 9-fips, 9.0-debian-fips, 9.0-debian13-fips, 9.0-fips, 9.0.20-debian-fips, 9.0.20-debian13-fips, 9.0.20-fips

Index digest:

sha256:33c00a7ee711d321987293d2e15dc0f0776bdb0236bbddbf083a1cd128cffa30

Manifest digest:

sha256:339d043890faad6ef72dbbd052e15bbea466dcfc0a64e44e0196139129e19774

Size

61.21 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/aspnetcore:9-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/aspnetcore:9-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/aspnetcore@sha256:527291260a6169fe9a5b010743e677bc6a54ded869e076f139a167178684dbee
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/aspnetcore@sha256:e7990a8c13b4bbba483f1f19fff3ecc5e88e0b51dce940d40240dd5849215119
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/aspnetcore@sha256:e1a96426abea46819edaa940c077f72ea213a99a8ec1da1e25b428c0109af4d7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/aspnetcore@sha256:8c8c6a972dc9f93866848f4320274f2e927187b44c56019d6f498f11f2f4c6fa
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/aspnetcore@sha256:d9f656ed642f188449ba565f70ca6b8b1ad8d433169414f46696e66d65a8f924
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/aspnetcore@sha256:95a72c37152fad601b0b30822ca3856e7426764b3de78ab8a358644d64cbe5cc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/aspnetcore@sha256:d0291ef24bbaca8752d03767b58cb1b96c29fd84c3e878ee13cd63b888bb71ef
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/aspnetcore@sha256:a4c7811c044ff3361820d0adbff3500dcc1a47f5a278f1508fec88ebe6b3d086
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/aspnetcore@sha256:2a56337dec3c24d840fd9078dc8c677bd68f36b6337cfd3b8d25c36839b205c4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/aspnetcore@sha256:1e1266fc6228a0f797fc3d5da8a5cba280b2915e88f0eb79501390bb0197adcb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/aspnetcore@sha256:81e626c3f23ea5fdf0f4e015908f753a1d2e17d05f060615213309b541c06403
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/aspnetcore@sha256:17837623c7088426217929e17c5d83eb6192836b006cde4d870995a5478379b9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/aspnetcore@sha256:be6394cf13edc70c81696a9160be9053eeebeda017b26356bfdd694e3a6dc80b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/aspnetcore@sha256:2057c49cf49bf9d0b8637526764822120d84c276f0198c2f7c037b3e96286bca
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/aspnetcore@sha256:9cf732112861a2ad7ae95f97432cb98045bad8d7ff7afc3b02f3606436af2493
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/aspnetcore@sha256:643d2ad4ab27eeec7291f5e7dd0d74ad90bcdad2e440f950b917ca1e8aafdaec
SPDX SBOMhttps://spdx.dev/Documentdhi.io/aspnetcore@sha256:fd1c344d0c77a5072f9460076760bc279be659be235eb011a7b72ab981acc62e