Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x SDK

CIS
linux/amd64
debian 13
Tags:

9-sdk, 9-sdk-debian, 9-sdk-debian13, 9.0-sdk, 9.0-sdk-debian, 9.0-sdk-debian13, 9.0.318-sdk, 9.0.318-sdk-debian, 9.0.318-sdk-debian13

Index digest:

sha256:d9e69f251a2cc9fa48d8a8a37f70ba6ae2b516b3d77a5ff8ccf2fda3e7ab43ab

Manifest digest:

sha256:91c5036831b88dd2a2c44967ca58559c1c5f4c54a9a706c69ca42481ec7a1685

Size

231.77 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:310c8ea2e4a853583566e31e5ae552a486983169bb99c857dac008225a94c6b4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:1711af5235baf7a5a176a508b28388a96dc6bdaebb831ae324e7ed87a879ebfa
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:6b4196f48c3cf2c3cdd2eebc6757f032b7e8d16cbeb6b0a42b64c9f9530eeb26
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:bb332708a8c3f0c2f9d304a62100d28f4557c7c442cffe2a78ea4cff4780ed03
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:6b8be122a908e4d43a6cec8e1bf044986e0cd0bf20aec838fbff3eafd330b57c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:4f675a58a794ce97849d28d400f501e8e50a9b00ab227df81b4dde8388eaed40
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:92b13edff94dd9c795692fff3f7d530bb025fa984628dd76852ced89dab3df11
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:248242bd10bc8da3ddffa5bd642c6bb2db4f90fdd21b9bbe0065a32ee17d36dd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:d837ece26aa0a9748362e6ac1c61e88c038a41fb086d25bdc4f173f5c304c8cf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:a2b097bbc4d008c158d1bb5466c96f650a99ea382a00b1df033076e1e1cbf156
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:940e9cf7b5b14d5324070d256fd5d713390979c973a83d971697865f97387c0b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:57c05c6fa7e0350c4ebd8946a2babb6853af073cd23448edde788467334e3a43
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:bd6ed7efd88c87fcf648f31d9342f2275b7099ac513bc124be560a32d703d9b4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:5a58c487756e9ba9c9121816cdca87aa0ce5789415dce4ab56691ad6c4e0390a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:11fc436705012d3b23e3069c758166882c2324b824145389e621a12f4c5b470d