Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x SDK

CIS
linux/amd64
alpine 3.23
Tags:

9-sdk-alpine3.23, 9.0-sdk-alpine3.23, 9.0.121-sdk-alpine3.23

Index digest:

sha256:8f62acc6e64fec8e32af26fac4281631cecd6670b28d4684deeb39441d95525d

Manifest digest:

sha256:9dc53beaea0340fad2fb4827a3d83f782dc6a1df225ca6b0fb32854a38529e5c

Size

187.19 MB

Last pushed

10 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-sdk-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-sdk-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:717968093821548720712077d51539b3c2b5b5a1c886d424d5da077c56d07011
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:bbfafa904256e187ebe4a063799d173e73fbb298bf397bc721a0c4f88bbb48e1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:75f9b9291596b5d29ea146cfbb27d00f3710f59d114043423de06d2c82834564
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:2ac7caa6f98d7cb63ba4553594b12c77d064345c5366fc0aa5c428946932f499
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:f7f5d391fcba943c8a590803f483422cd27f10098ff68f025515345f6bd7cad9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:04f7f323c57a4f977e0edfc88801ce1faa712d3f7ad041fa8a112f40789ead60
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:0564266fb2ebd937489e5edf786c3aff62c5a860f9b83a8c11e384dd9f8de7da
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:b27ebb6af0a868de4f19098d21cb20b5ddb3374cf3f018dcf8c644f96069f0a5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:dd6650e1968b511cf7c413aeb2c5881195e26ccea31c79faaf9dbe944c7cfb72
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:ac32a182c6f34db55ec9070c05cd74e4220fa9c9ea233fa5a2b2b75d9cbd931a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:f083812258f87f95ac069f9bea9328f035c73f0dbd852a94e98ec5beb0c41a88
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:ae80db8d2b32e5e3e5ebe65a97212b6e0bb844a19d1531416790cb0683a210f6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:a8b74486c68b559056adf0025c6c6ec30e14d11013b5ce9d0352dcb6076c4f2e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:f73cad850b25238b8ff8d0e8fdd75a0a1bfd133990359d4beae9844ca8e14dde
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:e98f596e23fdf70f380c2109e810c7f854e16e61a61e5e50640081c67b2a0907