Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x SDK

CIS
linux/amd64
alpine 3.24
Tags:

9-sdk-alpine, 9-sdk-alpine3.24, 9.0-sdk-alpine, 9.0-sdk-alpine3.24, 9.0.121-sdk-alpine, 9.0.121-sdk-alpine3.24

Index digest:

sha256:bffd901e40e645f11753cc4bd85b9d00d1dd3fa718266dfb0f93b2c05f95832d

Manifest digest:

sha256:33e62e641ab1da2aa30f90bf7454715f9c36299b8d1b27e0d8019b9760b846bb

Size

187.59 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-sdk-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-sdk-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:256565a999cee7ffb09858e928aba24980f211f6b4774d6e146e2983b3d6b9c9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:a30cf5b2e7b94e0b850c61343b4d05049971bbf82c3a890a989ad6185c3aa41f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:98a6792c8457445d9a61784d1403ba812267ced8913f136e20cbc6aaea78bc66
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:c51b0f0bef13f60911e6688dd8652d3e7db87eaa60cdc60176059f473971ba5b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:745adf5883b063d7bde82d278aebb1c4c9d560145abcca3f76ba1176430a45c0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:b7de0b66756267cb279bc071d2460cb91000406fa26f7d22ebd707fc744a0a7b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:8a0177e1593e67b92dc93525900e5840829aa67626fb94ba505f44a9ce35f26e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:845182a29fd3abfd9320a6df589441f4a6a5f9dff3e99bbea1578b6a33147bbe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:2f65ea068d3bcd11b9bcb8bcbda0aa0d240aa4ffa9829b96e2d9ef7c96e2e223
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:33e1c70d876bc375ffd2a25d21792880601991b95c73ba1b884a6fa889edf19f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:2278991e7a2c788e37750424620b063307cfb638b77070edad1dff10f45e2d7d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:6706722c8d11fb9878f845708f7baff6ee1425ac476e46012a068bc41687c656
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:1b8009f08f5b02429d79763b7344f38af420f67b299fce641a00974ad7f298eb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:ce81e8fe4fc3e897f0b37becfea1121af01c67f702974f367d001b1cc3c7f1f3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:f917e0c6d57064500cdc6c11cdec9ca6d381062bfcd7a0791f0469e3fc8702eb