Sign inSign up

.NET Runtime Dependencies (Preview)

Verified Publisher

dotnet/nightly/runtime-deps

By Microsoft

•Updated over 2 years ago

Preview images for the .NET runtime dependencies

0

microsoft/dotnet-nightly-runtime-deps repository overview

Important: The images from the dotnet/nightly repositories include last-known-good (LKG) builds for the next release of .NET⁠.

See dotnet⁠ for images with official releases of .NET⁠.

  • 11.0 (Release Candidate)
    • docker pull mcr.microsoft.com/dotnet/nightly/runtime-deps:11.0
  • 10.0 (Long-Term Support)
    • docker pull mcr.microsoft.com/dotnet/nightly/runtime-deps:10.0
  • 9.0 (Standard Support)
    • docker pull mcr.microsoft.com/dotnet/nightly/runtime-deps:9.0
  • 8.0 (Long-Term Support)
    • docker pull mcr.microsoft.com/dotnet/nightly/runtime-deps:8.0

⁠About

This image contains the native dependencies needed by .NET. It does not include .NET. It is for self-contained⁠ applications.

Watch discussions⁠ for Docker-related .NET announcements.

⁠Usage

The .NET Docker samples⁠ show various ways to use .NET and Docker together. See Introduction to .NET and Docker⁠ and Host ASP.NET Core in Docker containers⁠ to learn more.

⁠Image Variants

.NET container images have several variants that offer different combinations of flexibility and deployment size. The Image Variants documentation⁠ contains a summary of the image variants and their use-cases.

⁠Distroless images

.NET distroless container images⁠ contain only the minimal set of packages .NET needs, with everything else removed. Due to their limited set of packages, distroless containers have a minimized security attack surface, smaller deployment sizes, and faster start-up time compared to their non-distroless counterparts. They contain the following features:

  • Minimal set of packages required for .NET applications
  • Non-root user by default
  • No package manager
  • No shell

.NET offers distroless images for Azure Linux⁠ and Ubuntu (Chiseled)⁠.

.NET:

.NET Framework:

⁠Full Tag Listing

View the current tags at the Microsoft Artifact Registry portal⁠ or on GitHub⁠.

⁠Support

⁠Lifecycle

⁠Image Update Policy

  • Base Image Updates: Images are re-built within 12 hours of any updates to their base images (e.g. debian:bookworm-slim, windows/nanoserver:ltsc2022, etc.).
  • .NET Releases: Images are re-built as part of releasing new .NET versions. This includes new major versions, minor versions, and servicing releases.
  • Critical CVEs: Images are re-built to pick up critical CVE fixes as described by the CVE Update Policy below.
  • Monthly Re-builds: Images are re-built monthly, typically on the second Tuesday of the month, in order to pick up lower-severity CVE fixes.
  • Out-Of-Band Updates: Images can sometimes be re-built when out-of-band updates are necessary to address critical issues. If this happens, new fixed version tags will be updated according to the Fixed version tags documentation⁠.
⁠CVE Update Policy

.NET container images are regularly monitored for the presence of CVEs. A given image will be rebuilt to pick up fixes for a CVE when:

  • We detect the image contains a CVE with a CVSS⁠ score of "Critical"
  • AND the CVE is in a package that is added in our Dockerfile layers (meaning the CVE is in a package we explicitly install or any transitive dependencies of those packages)
  • AND there is a CVE fix for the package available in the affected base image's package repository.

Please refer to the Security Policy⁠ and Container Vulnerability Workflow⁠ for more detail about what to do when a CVE is encountered in a .NET image.

⁠Feedback

⁠License

Tag Summary

No tags have been pushed to this repository yet.