Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x SDK

CIS
linux/amd64
alpine 3.24
Tags:

8-sdk-alpine, 8-sdk-alpine3.24, 8.0-sdk-alpine, 8.0-sdk-alpine3.24, 8.0.131-sdk-alpine, 8.0.131-sdk-alpine3.24

Index digest:

sha256:06a6dd272a3c0bf9d56627f71a88b0b2d2fe75dec1d2e1ec735cb73b8cdc32d2

Manifest digest:

sha256:b255df10163b2eada1546bc5785da3791be66930026ca705b19ee67faa18ea12

Size

193.29 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-sdk-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-sdk-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:2d526aeb5fc73e924472ddf95a45f011cdba8e8e49cb8077aab6bc89f170f691
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:5423736f246f4d82998ffdcd8c95eb1e878b7a1a6a3d0b0906763b2f3b870220
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:e65a665d8facc7ce2bd1ab9dcff9ce58c8e0fcdc1a67aef989189ce8f1acfe78
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:f40823d911b92a5c97365bcf618a6a981616e409033babedddb75ca363d198a0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:c2c53d664f1993448f41fa434f90bacc57e3365067c0b460894832a8eeff2bb8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:42e2fa796b05729ee859296d67874a4edec0cd925c193de207771ae2c7ce2533
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:88b362032c767d650ae4500a1b7027f7d7fe7379cd5f569adf5488c492f8e509
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:ef347d02252b0b584ee8e4ec68986ebafc59c732f0cde7c4d885de21d1d8f350
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:db744cfbe8eec355763900ba9b91ecf9bb404fc6c8750cce1704e34479e86e90
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:1e5e2a9232e85b736801cf0e84dcefa0724d441c5d3e127f6cc84a7b933355cc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:4889edd4d0908d1c34bd68d109e090ce0f616346514e0b6b3b59650ce018ff43
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:8300ca30454d1ac5621f0ed7789731b8101047c39d4a5e597c3b5199e000524e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:7aee45f5f7cdc1375ca1697b61d1cf65bb33d9057ca53d600e733bef88540e56
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:6c9870c7787a6f53303c2dc58802ff33060bad2f27e61d1ed26fdbeaeeb86072