Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x Runtime

CIS
linux/amd64
debian 13
Tags:

8, 8-debian, 8-debian13, 8.0, 8.0-debian, 8.0-debian13, 8.0.31, 8.0.31-debian, 8.0.31-debian13

Index digest:

sha256:7e6e8ecafb46a9f2615f17290d00d09670005243b9efc24d35fd15d1d140b60d

Manifest digest:

sha256:542f3dd1b7a729606c170f765f453803bbbf475ee5842dd986acda8d3fe0daff

Size

49.36 MB

Last pushed

6 days ago

Vulnerabilities

0
0
1
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:43b3df842087a6c740489439073b7a78802e149a8efcacba877da189db7ba931
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:3c4c2934946dc60830433a2b866dc97b5cf7cdd81c2325429b5c5e5809d87788
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:198af7a53a0bedd354a59b6967cd27799982944250df35bb5007a1bb6c7875d3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:8d6e5147030ee09f8e3bd87b1f84e64f7ed10df29d4efd59e183c260fab022cc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:fa74754ad84f93fa3b3a4f45fea2a91ca4087bc68a5555d12080dabffb9f4427
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:4594862e6f01e5ff1e45f14478ade9192ae5083cb96768768c07939d4e937e58
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:36f4741614bc1f0e280cd885888b2ce64638d39afad2ab4acdd18b3635c53fca
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:802f8bd88fff1a1a691e5700ce33088d524c304e0da756216d7058d6700fb390
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:c1b2401575ce65c2c6959a645ebbc1c42b404ce28949f5c73b51210efd822538
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:620afb32b40802cac5187870545c9867a39c70e614dabded3ef31bb42253cae1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:b04c3e6566b5e159972f04d7000e9c514d31f0f9d5ffa7313bb520c996c9ddee
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:8332301c994a100c6e4a31cb435b2818d26eb9c6436ee04b237396f9d2c1bb6e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:9296abaafda6e5ed60847608ceaa2ed2cab02b9934627737860c7adb1969ad1b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:1a83c4fc31efd482655506d060b6ab58ae9b9b0cf44b7e08c3f79bbb7ef894da
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:47d0f15911b06dae0d6cc0a684c4436bc6e852ccea59832e56000b363806ec36