Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x Runtime

CIS
linux/amd64
alpine 3.24
Tags:

9-alpine, 9-alpine3.24, 9.0-alpine, 9.0-alpine3.24, 9.0.20-alpine, 9.0.20-alpine3.24

Index digest:

sha256:bcc95945fb3b161ef3c425af357dbf5192aed1d60e1c11a913daf4eff34953f7

Manifest digest:

sha256:5545f53bece9d393c2a53d2a6ea7a7c633974814ec5d884a2ee9fae5f49e4c26

Size

43.87 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:846ba97fd2b1b1691f53f9199001347c634cc16015b24b04b813dac007b99ac3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:4987da7a50dc995e37ccc4b58f1ac9a0267d7b712bb23ae5cc601cd9a130c0dc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:bc33886ffab3f7cf0f57852ef7d79fe5dae1b6981068c6d4245be664f320a549
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:72f011e87f952893f9ef7d307c5cdd11bfd184d3bd65e2e169ecbedb8b246d69
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:9848cd8037aefcff128c0223ed0fe90ef91c5cccdc05f971ee18742d48203371
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:86760dba549feba22fa9d81883352dad4d6e5f1b26296867692e9346fdaa4778
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:123fff1387b2c19b9f4bf7a4f5386bdf158476c6d716e6c583130b09e16bd34d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:473618c5f8265a38121661ec0dc58c3f4f8c0eb65cfd7dadeb52483767262e6f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:4949464ce17296c353ba9d8e52074c4ad4ed3f1bc140cb0cfc393f46612751ec
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:4f0f6b6785fa41199b00b732b9e2b165b5fb7e777a18b2d4900bac6751e4b782
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:bbc951eda3292981c449fcfbdcd1cf754e6dc5b4c19aac686498b1de338ce2ee
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:de900600551901092565e8aed4bca0088bb0458339a9b0e0203aa82b88f4ac52
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:b7a171f0e883ce57def70ef1896f9d38f3d092b84e31ca42074d50572e94fbea
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:6a059faa8275244fe28cbce7f2762bd94707863038422814e5d5fa5da98addd1