Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x SDK

CIS
linux/amd64
alpine 3.23
Tags:

8-sdk-alpine3.23, 8.0-sdk-alpine3.23, 8.0.131-sdk-alpine3.23

Index digest:

sha256:eda09bced5d10e7760936c230dc6f18262ecf2ec69e4bc2acba0658712e502a9

Manifest digest:

sha256:2b10f2b9b58efcce3705565c38731ab4bd82264479370c4dfaa6d8597e619d06

Size

192.85 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-sdk-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-sdk-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:4e5adaeb5044a7cd676c9301030102cce8c5ed6ee9da3605fae2404e32fb10d2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:b3d7c848ada0cccb4d9e43526c6ade3ce7e7d142915c2478920c0c9ee4eaf0d6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:3d1aa810c251886bcba893450e28c4fb5fac439754559aec9d4ce20757ac8e1b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:08fc8e250e3f493cc0353cf9d3ed28f4f1c02bf0e1903b017aaec926b6dcfddb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:b245081bf3e384686cb63b607da38f8e301dc34f2ab2307fcf91e6c89b6443f5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:81d8cdb5973919f91e105d090ad7bcd7605da2f852e51a8874320682fd0758ad
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:679a31140d4c6625336aaee87287ff46ca0061d25fde9961d07f665eae1df46d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:5db0485c45305c7fad9e2150f4e1e2d190eb1caf0cf07c0e93d5b7141e9f0573
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:7f29172c74451132bf2f85a34c8f386f9c9f05db9d7aa7443b9e75bdb35a192c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:e93ff4196b1e7a201a252da96245d43e2aefd82ee73c4c5c7dfec38305cef183
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:7633e594ce9e1338e27cf4d5b8cd7b2794a3e78d12d34f40ec2a2141bad69ce5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:d201a7e0f93fcba2568488ec2b9e1aa31730cc1343aa6e05d0520b36e6cbc51a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:18670654a8ed97ff2964263c5ff1ac9bb46321bdcfaadb847598de401e372dea
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:bb583cf58aa28b5a11e11a1cdf417d7e3e5594ed3028495ada8d1466de663486