Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x SDK

CIS
linux/amd64
alpine 3.23
Tags:

9-sdk-alpine3.23, 9.0-sdk-alpine3.23, 9.0.121-sdk-alpine3.23

Index digest:

sha256:c5ac04d0c1d6d4f1ccc2243c9509c650a7dfbf419057afedd05511cd6e45aab0

Manifest digest:

sha256:356d5da220447d204c29ae4e7be3336f22361e5128c27680a71f5f008e82f963

Size

187.16 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-sdk-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-sdk-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:947115f7008e7f9023e7270d6eb4c29e4e136ce9ee021bee094472db5467f05c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:ae90e704f79dac5f7ea2d0df1b3fc1121a6870ba2030bfaacc9fb2f823259c64
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:c2c6d5f8211d700bc6b1dc42a7775441a1aad3f45b7de7075670cd680a86fce3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:e81f088679a79e153916d1271ff5395e81ec49217a3b63d085c5b7b9a6e66aff
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:8c79612a7b091ed031e934baa0a1ebc4a0ca92a6ac06000f078c01202255a0a8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:c967aa9f545be450224cbadaed2728f6687a5758034b136c149fb78392e2ae7f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:eeceacb128751eb4a01f719226f05b473d6ea7252dbec1bfcbf2a6fcd8b86e28
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:9b4d077b151e445a012b333022df33598f7bfdaf3f94aa0465eb02212fb02d93
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:95271a4f2d90d83d00664686119e9f469034b786a3d802aba77147130e626ba5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:35a9bd48c78f787656297c94897f1e2f9b6095a8890072cc185d15d24ad98c9c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:098fb63e298db8042543daef23e17e5813af287f8d83503b213eb34a5ef86f7c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:3cfbfef1d932eb7778ef8ec5b1969c601f00d1c3c7addbddab6a03a2463000b8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:e7034f316dc27269b039cc47f6b6757ce35bce718cdfbd4d86f01bc84b3d306e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:e57a1e53cf79defe2417eb52bd55faec5ded9cb63ab91e843f86e1a2619d12de
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:0b66879eb89791e75fa9afb7a1f8d358548bd2a3dcbee8843469f57aab5e385a