Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

10-alpine3.23-fips, 10.0-alpine3.23-fips, 10.0.10-alpine3.23-fips

Index digest:

sha256:ddfc34800358899e647c6330173bbc056ec7371a90b74bef5a987dd407286d8d

Manifest digest:

sha256:d6b4f79d2fd5e9ec9ba1f3669155c013e37635aa8d7c63bac55fd8aae77e33fc

Size

45.40 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:5403b6f7686f45ac2b88c1cff7b79d081f0dc0d13574fa770e3c3ba3d27baef5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:a8d189c676c777e2a51b2492ebaaf8d7fd605ab60e26d0b9ffe9bbf2d1a9383f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:b692aa578c39c94534542cfcee8166b865bbd08a3214d2b07a1398e998c35686
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:ebbd7b5d5709abdf8e8b4acb1e4b31960695204d2d55d402a3a090b818ee8a9f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:53a1d22ec47fff7df2ab237da72cfc69348edd6eb41527dfebd2420e8500db7a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:c8f588cfcbdd64d7345205c2993aa51bc39877255bb341faed586591c86458df
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:240b6953212febf03b953fe4000e79b390d6d27ab1c3f344882c88a44dc3b96d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:a3367973176f102159f56a07f2c7dd9df13590bacc0eaef02f289b7b155e1ca8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:707597d38f701726e6d903f8026f7619797a08bb893e076c6e339dae80c60544
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:b97aaf5a12ff02eb660438e8b02819158ba6e84bb5c1d9f4b9919026294ec8eb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:2d0d5ae56070c3115a2bbdfae55a221a6c81cb976ea95b00adf853eb455dbc25
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:e7a96bd10a8106a5414b15f29bb0f736d6f740a711481f70fe8945c89ca2773d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:cd954166c6d99a187bdcce968da931db1cbfdecfeb48b4618f0ffd6ba96245f6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:979b6b5db4d1d325c691fdddcdde042c0eecffa3f2fc4f3996477a4af5b0f11f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:dfa250125d49a0622069528eb40c68376441907018a92cf7407af6756e8e1f3d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:a9f67c5084226a0e4f5ceced224ffd7f29c815edbfd35dce9253cd08dbb26439