Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x SDK

CIS
linux/amd64
alpine 3.23
Tags:

8-sdk-alpine3.23, 8.0-sdk-alpine3.23, 8.0.131-sdk-alpine3.23

Index digest:

sha256:b97b9bf9bc179fecdf97db9f04017b12f6e5f08cd3b41b90ef9529bd7a311d81

Manifest digest:

sha256:ca61e2d9a97098d806d77b34cbbcf9015523a8380700dab5651a0bde85ade866

Size

192.87 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-sdk-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-sdk-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:763daceabe458ea715136ff8c07e58c568be6808b5cd2689252782bd846a552f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:90c9f0344be137f06f682922d13abd44b9a3eb38cdb102f8868c7fb3a9e30aa2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:eb3d23deebce9fa361785b2180822cc6a5d3515fd54248a80c0f33cb6d7639f7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:72a4ba27ed2d5892b0f8c883a3ff31c07df961b4e237c5899aa06be6ba2f408d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:33e569c40d1b10354d0794cc021f02d7027b3602cd9e7b9052c173311c4fec63
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:d31e339b3f75a76888ce52dca873fd53bc7a34719fccef966fb2cf41ade331fc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:5917421496ac84d2c8b122424b958c4f1df2e7598c54dd1df8e4c5589318971b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:07f03019495571e0c3a9cef356780617f40cce714d7785d2bddb2cd42408c9d7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:127e7e9febcb20800e50187b248db3a66ac25c4df6ccb6765a2f52c3d541936f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:797cf408f1c536cc17548ddf17990ac0e0df32a843fac1c10ef4cf06a266a8ce
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:50598658d78534cfd0b89433ccd4afc463c380fcaad2acbb98e4a992d9885589
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:2de8850a1c10d741e159a1e38dc83361859092f46ff05e300bdc81d186ff9a64
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:2dec3485481635c6c56079ca9d0e470fadb6778745f4544bbcb65e48bbee75a1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:c94208f435f88b2fbaaed82b35d07287b25e8c62be63c68b1bd5078ceb0d8c8c