Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x SDK

CIS
linux/amd64
debian 13
Tags:

8-sdk, 8-sdk-debian, 8-sdk-debian13, 8.0-sdk, 8.0-sdk-debian, 8.0-sdk-debian13, 8.0.425-sdk, 8.0.425-sdk-debian, 8.0.425-sdk-debian13

Index digest:

sha256:0c7557886c140e6d9221284c1bccfe71ce59283cabbf917aa293ba7d64bb3c90

Manifest digest:

sha256:1ebc91b79beb49566cfb2a6a13bb6cdb42cea37e02b008248ae451e40aa7e792

Size

230.65 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:b43c2146e2cde7fa772d5705b0e5cb80afd48817d4963de56d4e80ac73760072
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:851248e2389c067bab5096ee0f36ca16e2ef8bad820832e9eae0509b6cfe1d4d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:c9df7f0824e64288cec860b1381b07c750622428d9af74158593d784de3447af
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:e01eab4935aea34f769c17f2f4baf624b415b41cd03f12a51d21593a02ac6e3a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:0aa9262ba16bfe0c783cdd068a77c5e28f00c627375a061a7d8833ba697b49a4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:fb5cd30ba6b33a58adbef6c7e3ebf19d77139360c208ba7320829e25d9ef9c25
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:83a5927efff3c4faa03878bfadacdcef79744893e6e555945d8eb3eb8315b8f9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:3e76676919fe4a0dceee878b34ef5034c60410103b1c0da54f0204f5e2975e09
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:abcbeef2a0ff433ddf5ab1bfca9abbc93ad956af36ae3059bb67ffd9a76f881c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:cbce821d7ac723404e00724f5e2459f7694620b9f9a1cc857a7272b0304e9490
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:c014ca305b16a53beacb1de22536821edfe018d3ab3bedde4e512cf9aac3e5c2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:4e5eb0c7426949232a350a482afe29ae89fc3c3c4462eb6a640deb934a70bec9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:d07edc904be5fa0eab76336d9179cd98f028d75ac8a87ea573faad555a255168
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:3df024dbc1b7631a1df064ee690abbaf424b5bdbb616b6e1dc883c2d55d97557
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:2bfa4f3a0bdd9a33381dd0664af6001bb9d0cd61d699c499cc35310771664160