Sign inSign up
.NET

dhi.io/dotnet

.NET 10.x SDK

CIS
linux/amd64
debian 13
Tags:

10-sdk, 10-sdk-debian, 10-sdk-debian13, 10.0-sdk, 10.0-sdk-debian, 10.0-sdk-debian13, 10.0.401-sdk, 10.0.401-sdk-debian, 10.0.401-sdk-debian13

Index digest:

sha256:be5089d1edecd340619dbdebd8c93686fbf7be95aff77c1adae92618ea9ac24f

Manifest digest:

sha256:e2dd03f4af09ed227c2cb21e55c85222fd7050eb91538326b31f6f2d0ad13e74

Size

242.74 MB

Last pushed

3 days ago

Vulnerabilities

0
1
0
1
0

Support

Active until Nov 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:10-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:10-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:13ebfe23f379960405588fb682a33b935da2bcd9f02ff34e1eb89e737a4afaf2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:2a14545c352b2001e9d73317b8a8820e050e788214285719e0cc58afe6826156
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:2849a7d2848b1d4603d3220d2cad15cc78280083aac1ae63423efc87bc1832d4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:1b8c8e1b2f74e394a0578b99dd83e8003d21ac9a0f918eb275b3c4eb46d6aec3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:aa7ff2b0cd748bf4d2c0026e60aa4996a1e167a5212cf20bb1938adf81e45948
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:e731585669299a4b5aa3ddffbdffeb26af225979a938776c455787f5eb6ac14c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:5d1bf56b8ee7647fb047b32e6964ae54dad974927e9fca773a4f0ff94e1eeb29
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:516b20f186a0265a75c15fb93c072f7def02af8d86658c9e31c1ec43de8340ed
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:ff5c8ac4f9124e40168b753ca225e78a4eee802ca575ff42ca51a6228dc5494b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:1098e3e4a2a999237f28209dfd257bd3165d4b159744671aeba775f7f021cb67
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:8c4f3ee753a20db367d423418e3e93ed04c3aa47b7bc17ac90d253e74b3d0b8d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:54d65817c95f6c58adf596d38bd8ad824db3f0fdbd5c2b0e6c5d45b3b9d60816
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:9050f97f2122a3d3147ee5a7f73010fa94fb919ebff1caf38f8e5a55baae6e8a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:9e7840b88a3ccfea2868d4478bab8bb89602edfb01beccee9488b0f9bbaec7d8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:f00283bfe9869237e5f08fc6bd8efddcd94d47d98fa341c24adc9c62a38dc154