Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x SDK

CIS
linux/amd64
alpine 3.23
Tags:

10-sdk-alpine3.23, 10.0-sdk-alpine3.23, 10.0.110-sdk-alpine3.23

Index digest:

sha256:03cc57ac8544a817606c4dd6f03952363b96b549f805da3292ce3b61ce455e74

Manifest digest:

sha256:b01bd297d41be6e20f588b1681cb3f3fa693c7dee730c255b00158824e0239a3

Size

218.95 MB

Last pushed

5 days ago

Vulnerabilities

0
0
1
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-sdk-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-sdk-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:3d8aaefd317b5e01ffd79cfb8d4e9372d920c1e49291419593badd776cd941e6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:c562b52fa09686ed8bdafc242ae7dd1b2ad4e5121b6a21e0b1ab13e62911c38c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:bcb56d83966bf5dd4a1b707684d1f6c6266af99a3de90e32c1bf10a9f307a518
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:9966f71435dbde55efd213981c99d93af3854af003f666faed7a6e432e019aed
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:96ddccf62265dd6b150112afdbe23bcfb123ba2090b5e665918ec3b316be0731
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:650f13f78f16cbe22a7ddfc935503345ba30c80a9eb043a68abaf0a93077d3b1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:f03154287cef9c1aa62667fe9f3aaa58e106fa82609f3b4b2b3b7fc9d5cd7b6b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:c5edab68cd73f9f10fb499832b4f77f8c839e7790e37a05fa4bef5377c01beba
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:b3036dab481dfc75cada0a8a16d1a931866cd522ba8e1b9e69c5bba0320ea9b2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:ac4d817c2817f41e5c6e8fd335450b090b38bf783170507db9f3525edf06e9b4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:05acedf5a340ff6e6c35e657967ed6ad81a644667427a9735dca2d9a18c52fc1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:cb4798e6f589a4ffb6dcc17d52595391601026193bcd58b94ea68cacd6ebe501
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:9497bc7f563c56f444595c8620e0c1bd271ed86fba5e8525ed55cfd76b6a433d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:56df8f9aed84db9ee8304f53f063bf3ae0be772561d3c0271207310349e0d5d3