Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x SDK

CIS
linux/amd64
debian 13
Tags:

10-sdk, 10-sdk-debian, 10-sdk-debian13, 10.0-sdk, 10.0-sdk-debian, 10.0-sdk-debian13, 10.0.400-sdk, 10.0.400-sdk-debian, 10.0.400-sdk-debian13

Index digest:

sha256:ce9b38d641ed4cce1f61bd7eaf32d018004ad317d33ac7b964a897ac10ea0c30

Manifest digest:

sha256:d5fda0712062e7830d92706799cb771cdef13248553247b8a3b161d74751ac5c

Size

242.78 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:f4b331a1e36e6b8f622bd3df10519fe24d75d3ce1959f7e6ec42f63bb5792b5a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:0ed23c008b2d0ab3b17da0eb344488174de55acdd4e8a56919ed6ef4c9957101
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:0ab2204ad1d5a4b6eb2a17a1b94e445a1e1b28bc105db6ce53ae98752d6fdd50
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:4b6de6fd733bee630d74151c1dcb5db2f9e2e3aadfc6cad27c32824e48fc0cea
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:42d214b172bdfb21ea369287e1e057ecfc09240f6fa4a9bf3b5c7f55c1decff1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:4c62d6ffe3fef038d5ecbb740677a04fe3444ea2e3422b3e0b44753593e40ce1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:0e12fbf9a68237bb2d230c1a2c7550e51672952c872b0cbfa61097c7dac3cf5f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:f04b0f847007ccf667245159692375f3f0100618a532822daa722f42365858ab
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:6ed72d251c297f297180f43b7556dea5c05ff89cb7ec780eaf05e41d284b62ad
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:8f4c0fd91c0d2cab8f6d69d915ffb88107de727e0384aa2ab4ddd570d8b427d5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:da1c89c2c0d87d73368b24b28c5a4ee8f4ba585774b0a5b08d33548bb6f4c8c0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:091af224d4716adb1bc9aceeb44556c545868029b3fc7f23d562a402accbe571
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:548443f43768359200e8715e7262f6d9ef3a378ca01ec62d6433049bacc600e1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:05cac261d7db33e83da8a74aed0620bb6bae52e3d0f80a89ccd3427eed4c6619
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:fac7ce7edcdbe9557dc4728d400a956adbd863a18a4cbc2110cba8471a9fffaf