Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x SDK

CIS
linux/amd64
debian 13
Tags:

9-sdk, 9-sdk-debian, 9-sdk-debian13, 9.0-sdk, 9.0-sdk-debian, 9.0-sdk-debian13, 9.0.318-sdk, 9.0.318-sdk-debian, 9.0.318-sdk-debian13

Index digest:

sha256:2c7ec545ea6763c94a0738ef112b0abdb1c0ea26331338a790333800d1b3ec10

Manifest digest:

sha256:3f0042cc71ad4ac99b110f756b8e53ee644783fe00d4798db6d8b4021955b4cf

Size

231.75 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:75b4be81eb4d320c22056409c2697b0f7e7a576fb63b616b1ec316972d3fec2e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:8dec2d54f5fe8ea62a32cec848d7283d03e14cf51a37a59f5bc03460a103daf1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:eb0a2fc4196b3c462fe49e9a5c4f51b5d3f54e8234d4153d16235fbe20871966
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:9b2c8dc22199bc628d53a1709693098b9f010f416795b76a98162e8af571602b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:1b994ef052ae6f14f926add180bf905009baa723af1c1cd7f882f3faa47aa6f5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:4f1728fdcc6339472ce68db61ed86ffcf0d6ae06cb688f1c1b6b43abc6d3f0ae
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:e403960e09dd420d543c22a13a352cc710c81812f11b08ebf0ebab8ffd5d6923
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:8217c4856fce0f31ad3a8a3bfa072e532417e86dbad66d5835280581fbf8809e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:3e3250ffca02a1e15d425e1fb19933795dcf047c2476135e0e64e43aa528fc8d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:14caac0c83f2ed7f88b70eb3e6207c56ff92990b46f34bd105b55c3f8683b8a1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:b0b5192ba73cb10e6fff463b4a6771693f5889092f73e000b5ed2dce54aa32c6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:358582d618bb1b40d62215dfb8c3c51c4137c5ac798bcd201fbcaf8f351bd71e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:756175bcdb8a4bbe9c24d016d67ec00eace08c7e428f4f2b4514fe4d75665061
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:581776211b98fc4e3b6be63fdf5ceeccad1c209310d58213580f43f03ac84473
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:eb7d2504281a7e73bee6230cc37e8d842ecb5aa25afea0d63842d2f514ec7916