Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x SDK

CIS
linux/amd64
debian 13
Tags:

9-sdk, 9-sdk-debian, 9-sdk-debian13, 9.0-sdk, 9.0-sdk-debian, 9.0-sdk-debian13, 9.0.318-sdk, 9.0.318-sdk-debian, 9.0.318-sdk-debian13

Index digest:

sha256:2c7ec545ea6763c94a0738ef112b0abdb1c0ea26331338a790333800d1b3ec10

Manifest digest:

sha256:3f0042cc71ad4ac99b110f756b8e53ee644783fe00d4798db6d8b4021955b4cf

Size

231.75 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:75b4be81eb4d320c22056409c2697b0f7e7a576fb63b616b1ec316972d3fec2e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:f53930d8837c6b9c7dd4b38f5253f84b80b3428865c723ae4a0828193964325b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:da50346114275c730893efaa8617b960353404831eb23c1a226b72f7ee3c7356
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:9eaff85ba57e590f33f9ce37100fde586998b706c07d622caffbea26930e6b08
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:42657aea830c7823025ef29c3c0b22174568bdaf52bbe293957db7aeb5ebbedf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:4f1728fdcc6339472ce68db61ed86ffcf0d6ae06cb688f1c1b6b43abc6d3f0ae
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:e403960e09dd420d543c22a13a352cc710c81812f11b08ebf0ebab8ffd5d6923
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:8217c4856fce0f31ad3a8a3bfa072e532417e86dbad66d5835280581fbf8809e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:68bb4d13f4fcc5d360ffbce27e153cc9b60e974a6c99a2629b7113f9dfa627c0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:c503c342c59935f306ff20fa06e83ae112b6dfc737762cb8ee49967fbe5cb05f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:7b76e60c1b8f1cd91c85918a0c311050d945b6a4d4710b59abfa5385d6ba1d52
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:358582d618bb1b40d62215dfb8c3c51c4137c5ac798bcd201fbcaf8f351bd71e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:756175bcdb8a4bbe9c24d016d67ec00eace08c7e428f4f2b4514fe4d75665061
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:581776211b98fc4e3b6be63fdf5ceeccad1c209310d58213580f43f03ac84473
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:eb7d2504281a7e73bee6230cc37e8d842ecb5aa25afea0d63842d2f514ec7916