Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x SDK

CIS
linux/amd64
alpine 3.23
Tags:

9-sdk-alpine3.23, 9.0-sdk-alpine3.23, 9.0.121-sdk-alpine3.23

Index digest:

sha256:55b2d1fbff26771f077f7a263f2269297b9af8e4a132183b52f23420762e094b

Manifest digest:

sha256:ee25151c2c6880d4d6bc2a3cbf670ce57233127b06e517cb0d67f2ebe71a1dbf

Size

187.19 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-sdk-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-sdk-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:a3f8a21a78773ee71bd3ac1608fda6f69cd2dbbe4b339e65834ea4c23b12ea33
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:b851d44bf4e9e8e1cc288b097a819a6ca77b84c915ff79ce29be8f281b845d91
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:c9f60d0d0d588eb26918427b1095320976f6cd7b2ddd069228efcc5442c0ca3e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:d53dd8dda2b4288e58027c82042324149fee543d358ccd323ca4703bda6b7a06
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:64c8b9f7e8636bf7425c2dfcd137e12265576de6c283745fc9cb218953a90c82
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:18354de86e0ba4b4257a2d379f6a2cc4498e838ccfe4879378a1f7824787070d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:a4fdd2d09caf3436d9e94555728ea866b75ebbe0aba501f18764797a267458dd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:792baaf23798a0514bdb8ce6258b0372d62a2869cead03b79b587f20a24b4ff9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:e15d8f76ab87649cb25e174b33e4da95dbe68193fbce8a46df67864dd0131b14
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:4dd25e59f51c2f466c4d4ee99a416e1837b3363879ced50741ead750d644e734
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:b7031d0993854c54747649b163c5d5cce747b8688be0dce5cea5bc61594d01a7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:3947226959e67e8e74f962f304d5e29216ec377e12ec670ce5b7348142476256
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:57ffc2543ed624b126f265efb5dbf1555b56d5489df1a54aa769cc361aa3dcde
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:e5b9166cf350f03d5c0c470d5f79ff2ea0979d4933341eca6accde148e617458
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:1a0cc56c3508645677031f2feac68ee02163bf50d33447fd8e0f0facfc5a47d0