Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x SDK

CIS
linux/amd64
alpine 3.24
Tags:

9-sdk-alpine, 9-sdk-alpine3.24, 9.0-sdk-alpine, 9.0-sdk-alpine3.24, 9.0.121-sdk-alpine, 9.0.121-sdk-alpine3.24

Index digest:

sha256:0de80db2b79ae4962c07b31c0437bdbdf24ea021a8941d401bec35a0b2971d6d

Manifest digest:

sha256:ba4c36d7fd717245442fe4bd30927b45340cd7d4c06551c92e4702757da8e229

Size

187.59 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-sdk-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-sdk-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:f76946caaefcfa74b41838404b66087db53b5ccba0c695517ba8b3f7000bedfe
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:10635683fb8aa4e5cef44b393e47159e0dfacfdb077d7f8dec6b5d86c53c2bf3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:7ba8d6c3b49c82ddd1dacddf2c2a0a96d23cc9796e0b227641adf653ef3b23b1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:59d12683a3cf9732bd83f2f0693b9c34d5c48faee1844af3ca97fa05ee28f002
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:ef13af6a34fef1e1112935f2645b47fa9038e989f0db1c0c5a200e2472179850
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:abb3049b7fcd096ba31d02c476ccc8dbcc8226ae9fde9a4bd914bfdddd5c9298
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:1faaf54a030a0da2a36f1d79916c7bf62467ab62406cbeaff921a239c7ad0d0c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:c68e17b3f7ba4785bac17350e15ef4b87ac96e42ff88daeaaf44ee81956f8c8a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:7778bb3593dec64863dadbdb113b0e814ad2b418bb59fee938c854840ad81365
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:6b9515834f2bd164a6353de2057ea24881a62f573cfb3c69ad511c5d319c4adc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:33e7010748288cd8dbf1adbd4d4c804ac304429adb608a99dff232a9bccad6e0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:6a34c25fa92e5a13925a9e1ae2c46e9ff82008d75cd35247ff9a518777f71642
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:f33326db7cfd38727709d580a445df1d292c86627f6be6aea0e7a52e5d07903d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:3306462fec9f97688cbbcf42efd0499f064debd127348288c3f7adcd3bf35cbb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:b4a00622e7642792ca4086139a62645de5f948d67bb49eb527664e75062fdf15