Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x SDK

CIS
linux/amd64
alpine 3.24
Tags:

8-sdk-alpine, 8-sdk-alpine3.24, 8.0-sdk-alpine, 8.0-sdk-alpine3.24, 8.0.131-sdk-alpine, 8.0.131-sdk-alpine3.24

Index digest:

sha256:da1c5a85a31dd1f502925736592d5150b0277ec0b8c6b661111a28f48f3dcc18

Manifest digest:

sha256:ca8e9a3fa2732d96d5642e64b04b2a6cffff5c7c20827f6af1f1e0f14b7c82c6

Size

193.28 MB

Last pushed

6 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-sdk-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-sdk-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:cc44fa6a085bc67071b2f688114a5d4cfb4ac4f23c6b8d891fec30d44ae99a74
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:65748a37929800a2824e930852659c4ac54626cc956d3ff9029e274d743519d9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:30512f1e61938e50b63d177901b628f9227180e2008e11ec94a71f3b754a2ec8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:024599d1a86d1292f9fa2a5ab97e0b3db46482dc29bd031b0138ceb3a29fa0bf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:3911ab14d9ddba9dca52c7ce16621da8fb847ca731a8ba4afc6cf8ba39e491cb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:b8cf160b1a3e57984182156674aa8d7e0bdc2c2558d32224b9662e313e5ff908
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:4f7dabc9398047c98f7c8347b00e8b60b347c3db0a841e8f4f4cb2d7eee49924
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:d90603b7a43c9f534b5360298654293a057f4a14440f70b4d1e4d7642f095ebe
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:0c6e4c9369b38a5394c82f7769b6bccc21c37b7737ad08be13f0e36153ef4165
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:ebcae61179ac826e8dc3c1491eec9e28f9618e08a48b58b633be415547ac3965
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:6c6a6787e271972ac16e67bd37359b4f56a76c7a97ca3cb5fb02fd2d4691650f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:36173a85bf2aad5f6170de073f8081469db4ff6aa09d69b86d906131cb335a02
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:944179cc81779c878aba6a9f78d6c932bb11b4af93f66ead04f04f4ccedcdf82
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:b63d03d043c9f31115bea3891488e4ae45c5464bc9b1093b789d2d3176406def