Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime

CIS
linux/amd64
debian 13
Tags:

10, 10-debian, 10-debian13, 10.0, 10.0-debian, 10.0-debian13, 10.0.12, 10.0.12-debian, 10.0.12-debian13

Index digest:

sha256:057634cd6f166bf572c5bd8e7f05a950ddbf50ce596b9731aeb6f3b6cfd34bc9

Manifest digest:

sha256:58177ca67c052128af497400db81da4e280fe2f6ab3cf45af53aca916bc3c4ba

Size

52.39 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:f720cd7c36aa6bda2a392674fc9bca92b4df04baf4de7cafc31a14b912130a31
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:dd007b81de6869aeeecd0c017bc36b47d6ae91131b69b4f5bc22c1b3c01583da
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:72e0bb1f286cbe3582c7224d8492fabca75dd6006949f0697113e2d9a13ebdb6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:799a61e782e0c8fea8e1d71dc9f17f30aded3cf024522479213e0d5ea3d9b98c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:f3bae13e53934c0c39a667ef6b888b03c3a8d424fa489d403678a2479380f9e5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:f9c0d4668811a8ad6c5e9d0377e75098602f6ff1e7e45b3c4f60a6438d925f39
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:b1553e6cb2155aebbae37f90f26d640ca6a521a8d0a5e2834206e017cdc1f53e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:b524c0dfe732f363bec20cb7e525a19f00d73b4c6b427af96db7c440f095b9ed
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:1cd832a7b7e04d4e5ec85df45e1b341de039fc4e83614656f8487aac0e9cbdbf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:d5b2f1077ab203834ab643db1bb7e99e43d703a868f044b6fb0a0b5d401cafc7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:4830564d1f789ce84f21525f11c3791e330e7e3a7374f256d2099ae3b5fed9b6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:9eff2bdacd4c8cbb0e5b4f0beb638b70c1fb421f86a1eda936938758f841ae85
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:59021e57dea095fbcb606da0eb38f0f12854f50b6b3f022f3e7d97fd5b528490
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:5717bee3878b9ad5a87ac8b21c8c5ddc23dc52f0353f69a4abc2e55515b85427
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:3f2f9cdc6c03eb0c70304facb4dcb4b614b05d79b511e982a94a2247cefc7704