Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x SDK

CIS
linux/amd64
alpine 3.23
Tags:

8-sdk-alpine3.23, 8.0-sdk-alpine3.23, 8.0.131-sdk-alpine3.23

Index digest:

sha256:c3d8622c6c0642893a297b6cbba606b92abde7511714ca0bfda1e57ce6f7f418

Manifest digest:

sha256:03c7f9e469120f7835ec7cf0b3ca94c67d6cfb86b4326c8ade2cf86343dbc648

Size

192.87 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-sdk-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-sdk-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:485bc77add8e08c19d2cd32ddc7185b6ea9d6deeecaf7c3c35c26d78177b2245
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:7adb2aef217f6229d8e1bb547091e2e9af13b2dfdc9eb25abfd3c8a3572ce454
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:ae83740b005e489a519fdbdb83db262e23662f0dac90c0d2ed3aea85205e4ecc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:76de7adc05cd386d802bdf565b612df944ef893b39fc19c748543a1048334fe7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:32685c31700aa2e108dc7f38918caec2a1211a4350c9b8c65e3ec44504628262
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:39278c271976fd1abc3e3a1601f72b20f1301481077a529a6180e4e31c74adaa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:3b7710ae3bb29592a5a73eb1950a890840063d8093b5bfbc4b8ef3f5087a399a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:32a15c38db4efc9bed2b3b44cd20e72d405552e4838fa973bc9a70edae7f8755
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:8179b18cd1d6dba2bd43f160631678c9ed6e77395b6ca4c335ad095dd6efd9c0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:a4aefc1ff2413c73ec11ecf4fd66cb475a75ed2c67d2c8e3429ef07b9e9587b7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:1735b57005751af42592415b7201a503508c9dc783e39fedd97bdc0c49955732
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:104d510b7f236d59d668578153dc51b16cceeb9b91167ebe10c7a0ef55fe0675
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:335df9a69b2732097434eed5ce50c7ce1b20543c3dbbc0b00e111207901c74a9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:1c65a5da96e83b9d4e9d0c63753ae32de76a3ec9aa239759e028f2df96b208ba