Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x SDK

CIS
linux/amd64
debian 13
Tags:

9-sdk, 9-sdk-debian, 9-sdk-debian13, 9.0-sdk, 9.0-sdk-debian, 9.0-sdk-debian13, 9.0.318-sdk, 9.0.318-sdk-debian, 9.0.318-sdk-debian13

Index digest:

sha256:0eca4e191af362a64811894e3b79eaac1dfaca27dfd943753db1247124932c6b

Manifest digest:

sha256:d17c5c6015d0c79b3b640e3ccf5c0961fa1c16e4dbc398e20a3f7a5586508576

Size

231.77 MB

Last pushed

6 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:4bbe5a6dc621df0caeb926685d47af25c7a0e1359726ffb38759bf72b9bf41a3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:0ad41c01239cecffdccd2427cbb70e4df055b170cb0b1832e41ea50307687138
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:acc8f31dddf1d200dd068f257c7909bdba7c23ffe23a5297ae9259c6ec6d1782
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:407802a1a137eb33d411a86d83f10f6423bae0759822508c3816ee15e9bb77be
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:b3613ca28428fc82443428f0a3f1b5f338681b7f37ad7e4e3c7644acc58fbeeb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:606ae671b39a596c66c87e764067e9dac8db9133bee648b667a64f59f8e0ca74
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:09ef09f485c0d409f2ae412c4b821ee2cf30590247ad5fcdef31b090077d03dc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:e659451f4e7b261c33e6f6ca93174f272d5f70042c505b51ef741e0b877d0058
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:fe4363dfc69647a0f7eafd55c69f7fc0c5851571dc20d037c785bb701a72dbfb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:7afd4c6cbebc944ce12ca8089ec7dbf49601cb12df0ee306945daaa1c8f29548
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:728db6b758d8455e465798c61ca6a59c907616d3074a6275a0be5913c326fff2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:070cf228cb8b7e3a577436bcb2fca9a081b8312848a505fc8e5763e0aada8b61
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:4d2fdc800127d6f1e2d634fbc73ab96d78e7be8c3775993288d2de1f9bf55dc3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:f870f9da328237e395d2ce0c8a142caceb9bb26410ad584df1401c31cbc8e299
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:30d6ca453db240bff26cb5ab17a16b5ebb3708b69f7c27776372239d5301646b