Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x SDK

CIS
linux/amd64
debian 13
Tags:

9-sdk, 9-sdk-debian, 9-sdk-debian13, 9.0-sdk, 9.0-sdk-debian, 9.0-sdk-debian13, 9.0.318-sdk, 9.0.318-sdk-debian, 9.0.318-sdk-debian13

Index digest:

sha256:96b4246dffab0a8fe284ceaa426e00bdcd6a830f24fbb344d6d8085f02f30794

Manifest digest:

sha256:3c5b1af7850a881a9c0f4cbe40d3adc17ef566002031d0970f8766ee2e15b7b4

Size

231.77 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:e815ae8aa6f396ff9ef639181a1c7d84002dedd81e350b0bd38bdd62bd6c3abf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:718a98a8497d704d98ae342fbba448e0c0659213e825308786ba2816144db0f4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:1131001b68da11fe10c9855079392c50b035777b1e3962865bb05986763b74ea
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:60925f83414bec1f69ef76cd86df3633018468265f0dae5e8a61fdb3ece6adbd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:a6e8bda71f4c7c05f78ffe07b3bc838a2a544631e7ec8e151ca960e259bc37a6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:deacb44ab540a0cff7121c1476263e4c797e2b80b38b97816903fd08aeec5486
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:2b927f3035cf1e3cab588ce3b61c61109969eca880c1a51ed976768c697cfbb1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:c54e52ffc534c5778ceb7274309bf55c81da36011bd8307fbb06505d6f91bb5d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:e802d327a275018b9306ecf8720cea9bd453a3938ac56c57cb38fe4a487d7794
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:6fb77b42c98baf437acc575a85204660abd37e53c0353d275ed6fa2957c43ee3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:0ffaef485030705a05dea42aa1161d388fe665a241b0336e91be062b7bbca9d2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:57bd2302a3948f0937944bc42d2b3938b0df120709d113aba0204364315577d2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:9221db4d20df87da787b9cd96faf210b5f84412827fe8a704bae61ff7437d1eb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:34341387d8dff4a025fcc82f8bacee20b199db9333a7e03a21c33df75e8025c9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:921bdc99b4c5fc797cc3dd2b35f823a639d7d6d1d22ad6616c6baf8aefb0dd9a