Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x SDK

CIS
linux/amd64
debian 13
Tags:

9-sdk, 9-sdk-debian, 9-sdk-debian13, 9.0-sdk, 9.0-sdk-debian, 9.0-sdk-debian13, 9.0.318-sdk, 9.0.318-sdk-debian, 9.0.318-sdk-debian13

Index digest:

sha256:e209618db95fd21b05765f53e292f195a466b2982a8736fcac500453b3a8ede7

Manifest digest:

sha256:eaa73ec19ab67594f4c6cd42df6c5bce82b62af523143c6a1d564844809fc631

Size

231.77 MB

Last pushed

5 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:66f44e6593a7538efd43f5fa444bf8113d8313c1581fdd7be570e392d963e204
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:f22a863d7518e9cb79e82e9fcdb994ee3bf4153fd3356b840e6760ac40b32f18
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:def08f6ba2611e4bb01cea4cb25ec4a04f83def29a4b9ed95f663fdbc63e724c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:ef0add248a5fd5f354d56acd73bc7a8ff596d06dbb8c16f4d763ba22b4aa34da
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:0197c734cf6106c0d2af7735386d719352c3bd0cef9dce9ed75e0c4a0cce3e61
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:00892755a7f6b86e52e18563e3ede813cae441ba3be0303b64a19d216c772f6d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:70dbd42a4b5eb983498175e28f0b05651941d60a0158494b3e0ccac9716dcdbb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:c5c071a410930d210d95a319e4f741b70c7fc7340fb848cd9b11fb9582cd17ad
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:48c4bf087a5532aea56bd3b389613bcceae0029964abb213cbb0560ac56eefdf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:87fb61fe0912749252d0f85437fdf080d6e80a51f67255c301b7b5bcfa51442d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:fb2aa8101bf44403e582a7b8b5e080e53168c910daae05d6b7429580be984dd2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:09f465e856495ce1ec8dd254e80249af34e1f01f6951572415635c2f9cbab57b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:739180fa3c6d24a67e29142f55fe806dc5ecaf048b7705bd6fcdc633522bcf35
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:1d9db6528a5c70fda509f8180627536c05754b904d5ad6997a3a4b74ca0e2624
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:4bedc4a9a5e7796fad3c5b5e16318247239a5c4db20c44026f01a449de764027