Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime

CIS
linux/amd64
alpine 3.24
Tags:

10-alpine, 10-alpine3.24, 10.0-alpine, 10.0-alpine3.24, 10.0.12-alpine, 10.0.12-alpine3.24

Index digest:

sha256:659f4d48249d056b6f1a38e83e3973e655e54786441f14ef566b3a948a59e976

Manifest digest:

sha256:da097473b2f7bf8d63183905579866a87aa6f3eb825dd00fb3c4357f8a150aa9

Size

44.60 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:8ec8a94782adb44cadc68c1952e1918c5d40bf68961d56b40486c5c0306e9f5d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:13fde1cf668bde47de34536ad2dad6506045be3e0e04c771fce92f75a95a8003
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:c52598a8e5cb1c0e3753032b4fbf7fd30a7fcd412be34ea5f138e52e18fb8dcc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:397a6ac92914039fca7f36d2fe690b4b0e859c7a573ab5ef0b816bf2a98a083c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:49c6b3b4df234d1ba4498030d4e9d2024f5532f08c3cba47aee9dcd42947a0af
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:c8995035b1ab1a7ffbee96ea594ec5c7b40ab20a669bab023b094483e623a914
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:e27f5ceead2257af7dec9abb3e553ed00cffb294578cc9abeb2cd603fe2dc18b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:cbf64d9d800011a2a56755a7e0489a84de798a947078d2a1a5781b25be97123c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:d910cf18b566e349d5cb33e07fc228eb9e0980324e291ec7a5b2ca682a847e74
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:da94590da6887b86f41c76e32e829587852838daabe09b7d20fde1821d1b39cf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:e40e28692ee5431492f960ae141c8dd260bc6fa5c8389023db1044c1cd96a359
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:6517c74c0e53cc0ae7febe6538f66d14209bd53a0ade74f2c3eff6b5410f9937
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:7c8f8168b707f2a457827a0007e7658959555cf82d262f4552e9b0dd2531ce11
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:ef2c92899aa3a1683ccce871b118b89dda308fa8cbaeb80b803f56c237fc6c4c