Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime

CIS
linux/amd64
alpine 3.24
Tags:

10-alpine, 10-alpine3.24, 10.0-alpine, 10.0-alpine3.24, 10.0.12-alpine, 10.0.12-alpine3.24

Index digest:

sha256:9a586d1b53e85e39b0c2552e084c098d47390fc016443dbf7c9704b2504e72e7

Manifest digest:

sha256:0b3b88833b459832be615422e743c55e3f5bae67a72c6ed399a6a210ce23a820

Size

44.60 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:a5e9eb8fc58a446bdacafa70d36b2f72de8baf52ff013be19ede67c10403dc97
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:1e8aeb8565ad12bca1a1df4d0e6a0724505394b674f9cdcfc30bfad3b78eec8b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:e49bf559caf9b6de1ce0044079de250617378d82efb37360eb36ca4374fbcb14
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:9d4ebae83a8403a04a31e5a13225ae3aef95a6b8ed4947df01578f1c01e5c150
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:ff5d94ed83147ea101d9e21ba8143bfd1488fe0420338f416406ea8da03435a3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:3d04f606c2a30141ee6fff893327e1c22bc2cfe96e8e2a20afd3e065767c9f03
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:d9cc3468b6a8b5e3ac81ad9203799641b970878aca5e3e940d8f0c9b971cecf9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:baed3e3b5b85c869f6f3ab5b175900e79646b15df69e90e1a5134df94175fe3b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:d9dffb107db1c2e3cfd62bdfb78087782ab08fc66acb936c8a38d97deefbfceb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:2e7379dab01c0fde7aa94358192e47e8ae9cd27f7a238757e5cca34f22936e7d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:0eec57925f9d3ab6b4944299b400b59f809097ab72bc0e85d4cc033035df8e4e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:3bfa239f6c627a7574ea77675436ab419f7173936ca1c727f7118ecf0f42ceaf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:4144a9d2e2e921fb9441727bd69a7a0e96a24f5a588b56a45c71b80cf7ce00d3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:76b5d45608577704d8d2e134cb143ce0dd51144a4a1d69af9f295cdd7ce3f49c