Sign inSign up
ASP.NET Core

dhi.io/aspnetcore

ASP.NET Core 10.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10-debian-fips-dev, 10-debian13-fips-dev, 10-fips-dev, 10.0-debian-fips-dev, 10.0-debian13-fips-dev, 10.0-fips-dev, 10.0.12-debian-fips-dev, 10.0.12-debian13-fips-dev, 10.0.12-fips-dev

Index digest:

sha256:87a48a68035a3fb6dbc0f6d91c057eda50bcd50ea53fd3ed14eb1264f4de4b36

Manifest digest:

sha256:3d8770e50a1cb56cf810386f60a4b8cc165de49c8cdc3bf823f0073f92a88579

Size

77.22 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/aspnetcore:10-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/aspnetcore:10-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/aspnetcore@sha256:26d7ba96f67c0a5a7294e965024fe7ffd79895aa010ccfcefb5f917be248b6ad
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/aspnetcore@sha256:10fa29b0641e6ba87c2b3e2d48ee0621758b2e6cdb7b28cdc248263c8ec26a89
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/aspnetcore@sha256:5fd339c40cb213c3e575a4e205e86aba0b1c8d4991f8398cafe3f2aba30c884e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/aspnetcore@sha256:6a740a1d3a716c7eddf7b3c92566ca2cdd4608492420455591f818fba20a6de5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/aspnetcore@sha256:3f4a56b6f0ecbea697d5450b380550748b36719639b1a8929e57679c02f07fda
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/aspnetcore@sha256:cffe576a586efe840b3982fb576a7156fac2f15a69a740a2687d7327e7f566d8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/aspnetcore@sha256:98bd9d5a1ed15dbf345c13164c7a5042e81ca96f55b501ca7e4ebacf417b2c48
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/aspnetcore@sha256:2404830f2427ec3668e3212dfff3d3b080c3a215969801dc183bf0d539785904
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/aspnetcore@sha256:85b9245a6cb2a9477d827ebea04cc550e8fb61d278ef34e465c6c6dc0a56aaac
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/aspnetcore@sha256:fc15cc880e6ee14a522f1b6a4693e4a61deb2ffd489a35dd4e9c1617d4df2453
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/aspnetcore@sha256:4323126f2aa508af7273041ac4c447f4f1462ab38b48379e64e8553666f1bb40
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/aspnetcore@sha256:f9ff740215275e5c39358ee22540a8b8c904dd6da310788e6d0e79d21f910fc7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/aspnetcore@sha256:bae632f73a9c80ae378394aeb1f38c8a06031fed2e2d8ec621b5bc148f1fef1e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/aspnetcore@sha256:4156b04c87176214398553552bba0324cb70c4a7c409c211fb54cd559f7e6f28
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/aspnetcore@sha256:61a5a82ce90e8df4b1ba2843995ce48209972aba2ca315ff33e6821e3483f35c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/aspnetcore@sha256:194118922b5ec47d0cd711287222534cb8ad1416fadaad0fe91f689951656229
SPDX SBOMhttps://spdx.dev/Documentdhi.io/aspnetcore@sha256:20afeb7cf1d6c6ab15b0406306d9327dc37480c39890630128e82033f2225e80