Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x SDK

CIS
linux/amd64
debian 13
Tags:

10-sdk, 10-sdk-debian, 10-sdk-debian13, 10.0-sdk, 10.0-sdk-debian, 10.0-sdk-debian13, 10.0.401-sdk, 10.0.401-sdk-debian, 10.0.401-sdk-debian13

Index digest:

sha256:5dcbed245528683a79b9ec7e3b769f98ed317c782fdf637f4c03798ec3a7d11a

Manifest digest:

sha256:30e15d707742ece213c0e58f484080214ccdd873882d427f15501e2f9e93daae

Size

242.74 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:276bdfbb7f87bd9a78d36f2c336dc441e9a1f946516db5f1f4ef233436daf98e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:dd23f2b0be7672a2aceab4a304724e4cc7b53039363d994cbdecac1e4218a2e7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:7adf1f56b6201e966a296d7a8df318d15580c1f0964bb54d4771f17c9e9dda26
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:c27d82aabf6b2ac2b748100e829aad771080db4c937035abade0d79945639832
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:5a04724a8a2da346b309e572a12d5cd5aa2eedd39e79c124dd691fbfadc2b3d4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:302c0af34b36ed5c6b17c2ec46bdb3866961d331865794aa302bca68b507cc87
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:c7b85be1718f8acd24718ac6222a60e2752fac779b9b51fbc9add5f524decfb3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:d0ec78a34259d7947aaea645f523b266f6c42d8a46ab65a5b41432477a5adab1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:c97da7e9f4e133f1f390fe07b3fa374202e426662f92f92c3573f711bda1eb54
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:8cf63003f0cc287d8dd998ea4919d6fa468cb10d3dda229f50b7969450d82d00
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:9c463c9c149309efebce2524f1607b06a63da32dd94301c22db4ff7947cc9fe7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:64cbdac4af8d4788abe81eb524eb6e96860175a6b1a421ab91d2f9df161888a7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:bd28ad0eff825ec541b14d15baa838ae700337091e3c806894f7f06735286361
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:26b2cb81324ff4a2207a4db8df9348995b12b342d8a5c0970e687030f2d8849c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:02606e505ca5a7a95a66610d550431be0827ccb4b585a9448bbb85e5bf6f6590