Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x SDK

CIS
linux/amd64
debian 13
Tags:

8-sdk, 8-sdk-debian, 8-sdk-debian13, 8.0-sdk, 8.0-sdk-debian, 8.0-sdk-debian13, 8.0.425-sdk, 8.0.425-sdk-debian, 8.0.425-sdk-debian13

Index digest:

sha256:a1e503db1a7f768a50747fe34a4594dc9901e0b8d59415f2b73290ad7e9c975e

Manifest digest:

sha256:0ea8a5d4c5fdfef59317993d5c4b227026772ef0fb78ece863655b489b787f18

Size

230.65 MB

Last pushed

23 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:d499e9c3ad960422ffe1ef38f0e55bdfda24521be7bfab11cd0f87a5e9ce025f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:0d2a10da505625d23773fc615036b31384c714a1f140cff62eba7d8780bfd7b5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:fa1d939d9b52dfa8bfe467727e133cd11747719129fe34a6ef4197e1a0d37ca6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:e484cb588b12a58c48659ac2b6d7a450ca1aea6cd8ffabf26b2aa21a8aa4d6ae
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:aa160b03ca9131482f2ab8bf99867ade3f573de9bd691773e5e78d5d9421b21c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:0d83af0afe65a14c9d7db6bdab507f91cf64cd34007f9a63774a5fccf92fd262
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:49e4e368444c7b15c0d107c719e56d8cee70ed846cfa8e70671435c10c814d09
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:5899590415d78c83c834b86cf87d601ec1a808a191443e62df1638c3bae0ebc7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:174ac49e683a81cb489719df2e602867c336f9d20111e7b48c9b12fa54812ad5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:161c0713aee47d36d32d78be1357de8ce2bbede258c170a56bdae04337102696
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:b4cd0f518ac745132fcc1f0ab4b597c22a6afa06dd1efcf32e9c09b13b33ec73
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:bf98cf3ef2a9c12abecbefebeabe54eb1f86f2940790c25a3bc592f37931705c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:707d0ada2d51f3546c58e87a2126593d76a770733ca99da420d59834ab38c378
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:fdd2448317bd923bdeaade267a32a570ad6e7137528c2e8ead6bdf5a57082fc2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:b681da871aa98f91753800dcf7a7b71b981674a30c273f9139b2fce5ee6374f9