Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x Runtime

CIS
linux/amd64
alpine 3.24
Tags:

9-alpine, 9-alpine3.24, 9.0-alpine, 9.0-alpine3.24, 9.0.20-alpine, 9.0.20-alpine3.24

Index digest:

sha256:8a55332d9abe6daabb4b8f264afd8af1f259690c60e3c64c2d7ca8235159da6e

Manifest digest:

sha256:745f44e1e93bc84ceb2e41bb31574e0394cfa03dde05e091692712e0266f6184

Size

43.87 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:5e92d1456753858222aea6af979e92f0a2e573bc6870657fb1772da4abfd1209
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:14806110874ad8fe6793446fd606571247591257edc5024b6bf4441f075b373f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:a3211879eaf4ab0d345615aa45cda7a5f582d29340a2034ebca96ad5388fe392
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:df3ac0f4d98aa071ce36c1d33bd082508434ccacab5a374a04da2bd5311630dc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:3ea71c150cd668e19cb5613bbb369ac8feedbd22b95f6ae9c534de3ab75d7870
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:9ab081e7d209d27e0e0e178ed745d11e9c46681260868553315c53ecdb46a30a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:433356310ac0ce7a04c76ce78e1ff6e092b216aaf90a77c3002d58c955f2cfcc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:2ed931fb8711d0de0befd5735d517a3b4b1023f70594e286901a6832268ad603
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:a994f430579d76e893b5604273801b5493a376a65810e48e120f3c2df484e0ea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:149b8e9f7fc6fe52284ce58cc63f304510dc3cc77b7bc3028bd3bc60bf56c401
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:5b6090bae84ae8aba33964dee6ecc3a6c335b11937add3470b9f16559a86a21b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:4787de1b1b62752dd3ee1c545a42d9b8c1e53f79b3b8bcc474036117ef8e754d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:c1ce27580c2d1ea5e297b11323129fb9a81342c9325c117ede1c2c7a85e19ef6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:c62324a38778474963c683409624922f7f0f8a9f4d04499055cc338c40bcfd30