Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x SDK

CIS
linux/amd64
debian 13
Tags:

9-sdk, 9-sdk-debian, 9-sdk-debian13, 9.0-sdk, 9.0-sdk-debian, 9.0-sdk-debian13, 9.0.318-sdk, 9.0.318-sdk-debian, 9.0.318-sdk-debian13

Index digest:

sha256:921fc69b2f8e9f5509ec6bef2598e7c6b73b57ae769910833624aeda83d65371

Manifest digest:

sha256:4b2804f291d8bdbe3244ff61e97730d5f56a5fbff018c37d06d9877818a4803c

Size

231.75 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:15b34b0d75184c603c9d9fe1e25874b287704d5a4a67d22387ef9376f46f0e4e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:cbb751393ff8943387981d6bf587075db6f508443fb5267b6c6b75b520a02737
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:be4439b2ba05494d31bd109f27a189b754f41d66ce3a9dbbad707b8c591e3cd8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:bb5239f18d78dedac826a32839f8a26da35483190b20bc576c3fa1de46a56048
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:9d754a85352eb6797c17fefb487cdf81860346ee47a9b0fd24c64c554752b538
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:8fd2f07f671910a6c33ad993cf776e52a7af656d28a64da904caa611eae13fc8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:ed61d0e5ccc7ed9ef01dd0d044ab33309a91083301e87723aa98ebb27d6a4c71
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:3a582c97fc660acf3093ed82a72ef9017f7f066b99b5c906349c14e5ed7c9fd5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:9029f656b0c3e0b6f73e5b0394cf005f25108e491e00d53f62eab757e71ba6ac
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:ec17b53d0b4f8b514524c717bb0fbcc9d52469e65cd9ee94f3a8da78cd2d6520
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:201c988a2e439e19f506f1a7180c0f121a5624ac512c85e8268b7941f4f64c71
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:4218e4a68261870118fd5b3e3d88d6fb1564194ad9a26b236e36f7d5142c773e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:d80bb22fe02898f1959847475701e500a31039368731e98d2792496cab4301ef
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:1f168124ec5fd87c190e6cb8785879918b6536d641cfadc0c6baa5e25916d681
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:80c2fe015ca6bd2f17fd8f061d1573d2dfa1d026aaae65e98126c9862ec2b1e5