Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips, 8-debian13-fips, 8-fips, 8.0-debian-fips, 8.0-debian13-fips, 8.0-fips, 8.0.31-debian-fips, 8.0.31-debian13-fips, 8.0.31-fips

Index digest:

sha256:0b048f7859ccf351251e9118b2a6bfe3738c9bf55e99ac7e3a53b4a6b923db06

Manifest digest:

sha256:23feb6044e317a5f2905a4ce3fd54be68a1c4a7e8bb9150bf54de15cc7f2ae47

Size

50.12 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:d8952fa1bf5328e4e7a410e294b5a0832f744a8876b8a821a59b42e956156a4e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:a8c2b20680f94c1d05be3ab8c648972e8d50cb277c8d321add81541d5ec49837
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:b710f23c6db7d82f4a2299b731d86c08dee65ee1894739f28558cd4624fe34d4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:1df19085dcb435bd3ba970f728dacd0fef52b651c9a4506731077a4489c431fd
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:6c41715f03c0a1d5b062d6c39f8a53a1b4202202c145583bd55e9560f90f6183
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:ab52138d77bfad95392519114683748e3dafea86252788d33d93846ea92317ce
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:9fc6970a5e445f586deb8e8195c2be8a45dc56d485907fe271c8a65715c34703
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:0b3fab82d3f72eef9395feb32d97dccf7bad9177f638f38d0554c19a863aa6f5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:1561b9f4071f9b3b701a5be89596c247c489b8e66dc7706c1d94e08bf304ccd9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:be1ebf83b4b62449f45c32e0cdf2ae2d6076d21e441d3d3fdc43cc053feff8ef
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:5c210709798113f87c017ab0bbbc1c542dda624311d4b9068a0c84752fa41d06
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:a994306fcefd7b0df688d22c3c76e1151150aac31c47c9532f936cccd687e95a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:2b61c4f001eab01367b4c798d608479e4d11de28a340fb691069b8e268a0ef1c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:31c4db0e93c141ac12bba8e049eb78b3f880fb68baeed73c1bd98f4b52a01a23
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:07ae2120fa410df6c5993fda7f05ffa53850a8b9d9966c3740daba1044b8af75
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:e0574c592f5707764becbbb9d767ad5bbe77e9ae23c0f9a2cd4577e3d5f5acbb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:03bc03e15fcb110453e59134b30ce2f04f1dafa31fd5e2f54a16c5c6d9ea231c