Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x Runtime

CIS
linux/amd64
alpine 3.24
Tags:

8-alpine, 8-alpine3.24, 8.0-alpine, 8.0-alpine3.24, 8.0.31-alpine, 8.0.31-alpine3.24

Index digest:

sha256:d40c677ade35c7fe26d932fe3e56202d2e3ee437313dd7b3382f6067a0771cbb

Manifest digest:

sha256:91b0f133335311238094d3fa9ff12a2c72ddb47be44828c57653a79585c589fd

Size

42.35 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:f1712c0535bc59745897bd7d70ef71b2ad27f1c9ef93b50e54ab05b96a086c1b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:d7a84cf7802cc06aa8519fc064e8560dcafd2ac813fe827216241a3133fed363
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:38ca0f522284e811271dce9b2c3ee86108ef2d1bd9494034fec03480912d58a0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:29f2a9719f5fa3d6c4beac9608fbff80596716469c4cca76302e254c5b1f6751
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:c55367c7391d742de21ec99769bcc8152671152d541be6412287f7f707c9365c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:cd9eb746f2c1f5349fe7a0b6ff335fc959ef14cebfe991a7161ed7b7b7ac034c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:5f2881ad26d0c4015ee8a3e1b19e98f12682a60ea0b7c9d45e78318597deb27a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:1ab7c1def3a259d19f5a5bc81107a2a4e13c7ae91faaef676bf32d24a4db548f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:2dff643a873c2c1f915212aa3f178febe881ec55e232a748baf18ff028576c46
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:a3b84657a77c05af891011cb88c6c65606092b28fb5af018984737073ee2d04c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:57bb13d8cca4df50bd7bb4db5984a0ad72c3472eec159db90e8c2238e4b4bc27
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:b0ba3d9065270c8f6f2b3fd8927221ee72f6c15ce918c4454c7835aa3158e37a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:23532894a61ce608271c38edeaedc0815ce278d932d983ae8c13787dd84cbf3f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:d894b151266cfc3000d81b38f898579be2a8c9a6a68b8ee770b9a9437168b1b0