Sign inSign up
ASP.NET Core

dhi.io/aspnetcore

ASP.NET Core 9.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

9-debian-fips, 9-debian13-fips, 9-fips, 9.0-debian-fips, 9.0-debian13-fips, 9.0-fips, 9.0.20-debian-fips, 9.0.20-debian13-fips, 9.0.20-fips

Index digest:

sha256:03874e2750bfb5e79b24afc15aafb1e21040495d511c4f30eb60b3067c946c13

Manifest digest:

sha256:90620d6445f4cd6771ba4813c428f53d79de8f045e7628913531ade99d73d93d

Size

61.22 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/aspnetcore:9-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/aspnetcore:9-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/aspnetcore@sha256:c21e68ed3fb658b4324befa33b93b7b14a7cf924086b49bdb628deca19ce31a1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/aspnetcore@sha256:a8352a92ffc7e9fe9f5b3aa2e051d90a150caa5f88b090e6be4dd47a8377909b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/aspnetcore@sha256:31bbb8b270de61737dffe0fa09fffca79bdf45157b1263e8529f461aa5b00b16
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/aspnetcore@sha256:93727e377121ef06c4cb6f6ee4aeac91574d1d7ff4bbbdd9c595fd0595b1b6f8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/aspnetcore@sha256:7fea7d970878b23c317c55794ecf8b40ba14e85cb047b6bb61737e2c240565ba
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/aspnetcore@sha256:56707296f7cd033405a137ac597e6c62321278cc03bb47ae610d1532a14e85a2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/aspnetcore@sha256:f4b0f2b9acff964ac3d2b1fb808fa11d5bf8ab1cdfd8311d414820d6e125d539
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/aspnetcore@sha256:b733e645698a70ad89523d3ed58f719f60069605e996c418086ddd28d3af14b3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/aspnetcore@sha256:50da91a7845c45cf1834d469955fcaa4a63e5d4744e2dccb824bad5699f2b6ec
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/aspnetcore@sha256:480b198dc70cc69875a5e4ddd909e83871fda6bae1bc191d1fdab7fa36066fdb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/aspnetcore@sha256:15af0bc32cb778f4fd72f4409f1a214a615d18908af489ff7ebe6c8fbe97e639
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/aspnetcore@sha256:de0193a8c45a964e932e9f086735742116c83162b7d6c97e8b93035e1086bdaf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/aspnetcore@sha256:c2dcb95f8473e1574a594a3cf211e4878a561d45336876974a420076b02c059f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/aspnetcore@sha256:f99dc49af863576a9098c1dacde11e3a828b18363f31c08e644f771d8346f84e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/aspnetcore@sha256:fc134ebf575c036e828221d8f16da58efd3306bddbd6093e1438a9edf8b8eeb7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/aspnetcore@sha256:98810c5f7593377b8acf5e4218c2d8a7974df317a2a900e3d7847485547cef08
SPDX SBOMhttps://spdx.dev/Documentdhi.io/aspnetcore@sha256:e1f9fe581bb3bf55e1849064ad37dbb8538056f867af7f58a4ef8224626585d9