dotnet
Runtime · Language runtime · standard · v10.0.110
Hardened .NET SDK for building and running .NET apps. Use as a build base; ships the current LTS line (10). Image only, no chart.
Security report (Trivy)
Security report (Trivy) · dotnet 10.0.110
Published versions
1 tagEach tag is a multi-arch index (amd64 + arm64) pinned by digest. Tagged by version, never :latest.
| Version | Size | Published | Digest |
|---|---|---|---|
| 10.0.110latest | 271.1 MB | 2026-07-21 | sha256:1344024b5aae… |
Use it as a base image
Reference it in the FROM line of your Dockerfile. Nonroot, read-only root filesystem, built for amd64 and arm64.
FROM ghcr.io/quenchworks/images/dotnet:10.0.110Or pull it directly
docker pull ghcr.io/quenchworks/images/dotnet:10.0.110- Version line
- 10.0.110
- Latest line
- 10.0.110
- Architectures
- amd64, arm64
- Runs as
- nonroot (uid 1001)
- Root filesystem
- read-only
- License
- MIT
Verify the supply chain
This image is cosign-signed and carries an SPDX SBOM and a SLSA build-provenance attestation on the same digest. Check all three before you build on it:
# 1. signature — built and signed by QuenchWorks CI
cosign verify ghcr.io/quenchworks/images/dotnet:10.0.110 \
--certificate-identity-regexp 'https://github.com/quenchworks/.+' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
# 2. SLSA build provenance — which workflow built it, from what
cosign verify-attestation --type https://slsa.dev/provenance/v1 ghcr.io/quenchworks/images/dotnet:10.0.110 \
--certificate-identity-regexp 'https://github.com/quenchworks/.+' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
# 3. SPDX SBOM — the package inventory
cosign verify-attestation --type https://spdx.dev/Document/v2.3 ghcr.io/quenchworks/images/dotnet:10.0.110 \
--certificate-identity-regexp 'https://github.com/quenchworks/.+' \
--certificate-oidc-issuer https://token.actions.githubusercontent.comSee the SBOM & provenance guide for reading the SBOM and using these checks in CI.
Best-practice Dockerfile for 10.0.110
Restore and dotnet publish in Release with the full SDK, then run the published output on the aspnet base for web apps. The SDK and the NuGet cache stay in the build stage.
# Build stage: restore, then publish the app.FROM ghcr.io/quenchworks/images/dotnet:10.0.110 AS buildUSER rootWORKDIR /srcENV NUGET_PACKAGES=/tmp/nuget \ DOTNET_CLI_TELEMETRY_OPTOUT=1
COPY ["App.csproj", "./"]RUN ["dotnet", "restore", "App.csproj"]COPY . .RUN ["dotnet", "publish", "App.csproj", "-c", "Release", "-o", "/app/publish", "--no-restore"]
# Runtime stage: ASP.NET Core runtime, nonroot.FROM ghcr.io/quenchworks/images/aspnet:10.0.110 AS runtimeWORKDIR /appENV ASPNETCORE_URLS=http://+:8080 \ DOTNET_CLI_TELEMETRY_OPTOUT=1COPY --from=build /app/publish ./USER 1001EXPOSE 8080ENTRYPOINT ["dotnet", "App.dll"]This Dockerfile is pinned to the 10.0.110 line. For the line-by-line walkthrough and ecosystem variants (npm/Yarn, pip/uv/Poetry, Maven/Gradle), see the Build a .NET appguide.
Upstream project: https://github.com/dotnet/runtime