Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x SDK

CIS
linux/amd64
alpine 3.23
Tags:

9-sdk-alpine3.23, 9.0-sdk-alpine3.23, 9.0.121-sdk-alpine3.23

Index digest:

sha256:27a87a3a4c21b15da0ca5995cf172e4757b708fe91359eb40949e5073828f8e7

Manifest digest:

sha256:51ea9efd70168f8560a079bfb03c7f39760764fd063d93125579415ca50a0bd0

Size

187.19 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-sdk-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-sdk-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:9f7c8f3281ace5953639edec174075da2d83bed3c2e5d382602d8068ce278616
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:5ebfa5d0d35dcc906f0db3fb0f49c9a6b08edf64d94bef44ce7b51ea702b2dee
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:96e1fa0ad5e4d67bcfa256ab6fe7ba0ad61ee2f025f9dea3a16f206e55ae42fd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:7084fea1802faec5ad27867207962b93bbd3c1f54356dbe49cc552e859a6b3a6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:b01b41deabd42fde58f68ae61978b4cdfa0b174d9c2f856822b1fada77bf1cfe
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:c8c8f6ae55101a90941756181fb9268e3a4e8a4e0bbf896b8235c0742319adef
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:dc2f271b5c0e8d0cc7219899619c61310662578b286be720a63ae2546a6b45b6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:575c3427bceba8fcae056ada366ca5e62b5edc33f9c50ff5e998c29a61628c37
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:a7a84c0a99dca33a6c08fc1f10efd870212f3126c126f7dcc192591c846b417b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:b40ab9e56164bc4aa224b530fc6a95f14a5e54117a58d5000435a46420276fe1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:d7d42a3131a9c12fa018aacd429118236649ff4b398ff629a593c333d106aa4b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:4edcac7f49aa6dee0648e7cff3ee2e88da5c60cedc9d6584b7bacecc1577348d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:7731285c3bbcde50b01c8746e20866e6d7e71ede57c4c128243acfc6497b2b64
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:e2cdda363bd79b1af5e7acab5d3e1bcfbd10164487558e7b0979a51975db7c93
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:c5d6e06142b518884d95105b356fe80489b20ddbdd827669f1598dc1208135d2