Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x SDK

CIS
linux/amd64
alpine 3.23
Tags:

9-sdk-alpine3.23, 9.0-sdk-alpine3.23, 9.0.121-sdk-alpine3.23

Index digest:

sha256:cc838e223a4d0f64db7562ac9baae546beffe9b30a1616823ed9cde8854822ba

Manifest digest:

sha256:4b5dabe6c7ff1be1105827be597e7e7d2a8c13cb07c48bbd02aa93a975324af6

Size

187.19 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-sdk-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-sdk-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:08f124d3c0823c85a8fd35276bbd1754e915bd2b742c2751aa4244ad9ad51095
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:d1d23c8270325ca64e7fd4ce921cf9092cb10717777449449aae5c9d2daaa6da
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:61ed9cbdd54dc7fe72b0807b59fdbca13e0c71eaf878b922a6ad4c3453bd438b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:1ce568b936e984e4a23e08c322e2d4df6808cb07ca040d2f8b96738afba33561
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:6bc9c8893a4ea375ecec8515b5b3a1a55ecab5bd1de8555156135393c418f805
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:397a8f4d61f548a7651f3f8ce1fcf3894f365548537fe3049f7e6f9e8bd6c551
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:3f3d96aa423a9b050bee473b4f050dead26a433ddfc09e24637ee0c5024f8928
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:dab472f548cd201a6f368fa1b84fbe6123c0377ce388500a198896bf87d7b801
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:4b09dd9bc1a4f69ad68638e6c81b720f8e54b85319254b27c6eef329b12712c7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:6861d6541e7ff73e05b8fafa4363262b78aa90d8b501aa18b570951080861288
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:cf5aaa6906124c1df64234dbfb892d1e51a43232ba23f1eeae3cf14b9ec40002
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:1895e4d788ccf6e1dab8b9c0997086cefdcd575ae361dddb860a0a970844331f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:6db57a7035f2e2173ba4cde9576f678053b88d8675b4c1f5c5fe85d1f5c959ab
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:c7c772ec50c6cda1869cc4d1ff2a4769155d79d8703683a637c40ee1b81db63f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:e4e84bf4f289ae0850283ffbeda4a97791884aabb5ea3cc8822ec663bf30f567