Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x SDK

CIS
linux/amd64
debian 13
Tags:

8-sdk, 8-sdk-debian, 8-sdk-debian13, 8.0-sdk, 8.0-sdk-debian, 8.0-sdk-debian13, 8.0.424-sdk, 8.0.424-sdk-debian, 8.0.424-sdk-debian13

Index digest:

sha256:f214e070310c108286d2b662586ce783e5854ab33519f368076125992c5905b0

Manifest digest:

sha256:5976ab6f1cc6cc9d9aadecfe30a2dac3312309aaaad80a5562064eb82b272653

Size

230.63 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:e0a7012da9dabedaec3ed966607e3cbee856e4355cd026ad037ebe120b9a5447
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:c8e4181b948fe5d0c6b10cc59c2c11d5077b2227c109290b5611c6364c5dfe0c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:cdcedba593da7a496e103c9ec1a4c776e6cd3e9fef292288acc6c1a0fce94f91
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:b531caa01f1736e49efec28faa8e6e77d526429da230e8d7f7b1b0227c637e9e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:380e30625219ac3cf1d51651ff0a382170bc8c46a18b14e9ab44b652d96c1538
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:ff0b325936d1ca36cdcd3eee4dbfb646b5076d4ebc6e0bc57db7858baad42397
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:dddf0ac3ff9020f5e107e1dad85b18de08da47bd9938c29d10cecd87ecfc12ff
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:ab94ed22e6a6ea450809c4b175085aee126a5bc4b78b7a3582b07d4e66d15ede
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:3235902bf75b842a3d26f0dcba07dc5284faee4f5690753ce74d8fd350bfa41d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:94b8f1ea39aac457046ed7d7cad6f45a227b04f00fbc1b829e25b5da34fe93d7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:a4706d873f6368e3f0e2445f9557c254871cf75bc07f209dc8c2c05a5b946e8c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:c3e10c9516a96a067da6afa94b26896731628c7346279ff2bd4b9ab523fb9a2a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:d4952bcf7bca9899c5074a8f3b5e41c7e38b8beceac082a4c2529d43e99c4d50
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:73329c7b84361095e750732477ba087c496e61965f5022ee080c5eaf1ddbe983
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:783d614b7de6c47d2126abb5b7821f443cb40105140021f1b369b34db8eca292