Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x SDK

CIS
linux/amd64
debian 13
Tags:

8-sdk, 8-sdk-debian, 8-sdk-debian13, 8.0-sdk, 8.0-sdk-debian, 8.0-sdk-debian13, 8.0.425-sdk, 8.0.425-sdk-debian, 8.0.425-sdk-debian13

Index digest:

sha256:10835178635e538ded6e26b1bffd32ef67d0cff73a986f5a24baba41098a1054

Manifest digest:

sha256:9152ddc6798521ab81b15e0abf1aca04b04d9b6876b00eb2b5ef7aff190f8205

Size

230.64 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:6cca2c565afd2874af04e0983a05882af650738988a858e6ba8e0a4dfce2303e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:db844daaf04778cba5734bdf064edd9e4b2d1bb2d83518d67619dbfe2e373950
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:918b5428529e8267d1b5cebc76de4a352d94f019175a72eefa474ad9c8b5b350
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:a04a841b139ab50b6574dac1218fda4fbc7eeb05c8ec8360a84f76cd8a7a6e58
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:75dc94aab742d8cd1ac465caa37bef397c68b0856ec18ae32895a3b28c310470
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:ff57fb12548c83f4741049af4da5b3b8c9a8d8199a6b5fbe7dca850c1df1dacb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:cb9fc146d34aef4ed7e4879244b7a28fb32c481a930b12e697b3dd23ca82adab
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:1633781cced40b1514f1b978c17cb39823be6c96f4a30e329aaa8ec49f7bf89b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:921b7ec716f32512f3cb9a3cf853c503b4b75bf0f3fc0fe10e2e1d6c1712272b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:bdf402039c15ec19aba456230667567dfc16234ec836e3539db6ea6c4a65fcd0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:25df1772babfd76d6f55f0f7d63982fa7d1c225a0f135e366f568e427b615823
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:0faba21accab0f56378c5527acceddd5f5ded090bdff6b45cd180a3dd4b00ab1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:4721d9ae802850cfd9a270cacd5e9738a980cb459744b71c61a08172fa759128
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:5f2beadcf72b77d2b6e94708c3ce3e3a9dfdc046ed970aa6a8399fc73d7b749a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:51a325b8d9d6028a1a8be7a109cbfc8889185804b47b13a4a361304fef24ad49