Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x Runtime

CIS
linux/amd64
alpine 3.24
Tags:

9-alpine, 9-alpine3.24, 9.0-alpine, 9.0-alpine3.24, 9.0.20-alpine, 9.0.20-alpine3.24

Index digest:

sha256:214f9eccdc87e58d9cd0d6c4cd9482ed453b35b6fc8c2ecfc703c4a245a24eb0

Manifest digest:

sha256:4a0898ad943748e0c1a76f5f8fa40ef567d8f7f8e0425ae95098bc075e1254d3

Size

43.87 MB

Last pushed

6 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:6ccb7dbb96a58381cdb6547b85a7ee63fd7330160c2b724376d90f6e29bb2a1b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:4be745c21bb7cf547ccb72df6abaf754fcc3d36536cf4cb64e6b695b3b8d0445
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:f42fc2836063563de8150299f55adbc58f2dafe863f54f92cef4ff1b7c7d8722
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:267ba751c5faeef526942e970596f4fbe6529abf8d9c14caf1fc0f69c653c8a0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:9a61cf7a939c9807b70697bf2632090854f220191000b332adc83460987b1637
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:2573cafc30fdb23cd06eabdef1349315b121f8db4b1c430d596e32381c00be85
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:a98dae842564c523e7163db4ede74c4258ff252d9451f7fa53ed92b07619870d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:8ebf214fc30b4ebf8ac12069e7051e3e48ac8cafb9108ed891a1924eaa4dca58
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:d2749119893101966c3da5cfeedd512c556c7a24fd5ce6a4cd7e18dc40db45de
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:d40be82df52a2d88dca059da149b143f9b925cc5816e653d64d9838fd5752a84
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:5badf6757b6791fb0974bc19151fbdf1cab84ed009363e001efdf3e263cf14f3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:26f7c433e0873e4729d86e5daa17812776a3ddcd1b33e1291f259f7f3fe0a54b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:96082eb223515801266a7355d4036124097afcc46b7e93cada13838216a8ee07
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:fc30e8e3d864daa31f5e9753aad29a72e39ce12592ad3d002c0313d57c779b37