Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x Runtime (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10-debian-fips, 10-debian13-fips, 10-fips, 10.0-debian-fips, 10.0-debian13-fips, 10.0-fips, 10.0.12-debian-fips, 10.0.12-debian13-fips, 10.0.12-fips

Index digest:

sha256:50fcb790eadb50363ccbb69236119d3d0b5fbccc865f09fe3d17184e762b6b0f

Manifest digest:

sha256:fd1c72b5079160b45a8057f0bacedeed4b2ed3ac10b4f850ea8f40f800704f06

Size

53.17 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:d489cab30fc1db0fcf276696d0663fc4d3ea3b982951873da3f415af6306f1e5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:8041607499eeb8ae22f69dc73cd783b0044ddf65c5e15399b38d82f655b8bb0a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dotnet@sha256:2d307936d8a35111a04b3c593d79568659bc9b07fdc41dbfab54caca8c5db543
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:4189681665eef8bbb224be3ba15e2cb6bac0811a17366caa83cc30d1cc3d51ce
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dotnet@sha256:47f87cb11446ac779b9d0d397c2927af95370e2d4fb7ec8a4e5a91f0eaa38a81
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:690576416e28cdffa154625a3285c59b61bd00ad194618cc279c5ef78fc085bf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:9ea3f1e4d2835fce7bf46250ab4abe874eb7b23b3b47d4a2646c830b26ab5ae8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:a27c413b842c8751a1d815ec1c75a3ca37d221f8468c4945e358717c360f57d7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:d891f74b9d509916626bd83b9d0fbee0e0dccd4195b584a5cfb7180002fa0caa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:ff20cc2561c1d61221a09d8b11c7e4968e6167c472853476d5031cd13d961ab1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:1081f33c829941a4b5bbeb20e9a50db5e96b02d45d7f315e169ce5d42bd24b7c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:d216730584540b6d74b08b40dccecd0db6a81a89eb9be7a5eb515f149b3f2963
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:8750c4d7f1a4b46d0c8dfbe65f6be4342cd8615d4acfcc9b32322ee7f3b2a266
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:0b862a1c96e56b3595e34f991e17aa5efc3564e611041077d12a391cc8950c43
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:51ef4175adab6743b4b879c710abca14d221cf89353935a19642a55b1b05bf28
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:59ad083c2ae571b54f98a25b6a1b7f7a8ff43aa97089f472acd2c9088cd24dff
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:57f83b1bac3862aa8915b3f94641f27fa2e068a423c9ade4fa87c0f35a10d27e