Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x SDK

CIS
linux/amd64
debian 13
Tags:

9-sdk, 9-sdk-debian, 9-sdk-debian13, 9.0-sdk, 9.0-sdk-debian, 9.0-sdk-debian13, 9.0.317-sdk, 9.0.317-sdk-debian, 9.0.317-sdk-debian13

Index digest:

sha256:f24c8a39c8aec32e6f7790b06492e08c8b82da41f8d3b4ea396bc4089a06de5e

Manifest digest:

sha256:cbacf3b5311804a11a2a61ed8667102800d4f0a4fdd8eb16d426e93cd4a22da1

Size

231.77 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:6afc9e0e2d95ca702cfe808012e74073c79c3128cf9da39777188b790efeb04b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:46b6ec07022ac2aa93e6e72ee3c77e671f07034cbda46869461beb75d12ca979
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:3c30b9b48c05c454955f4d67a5b3790d424d8a871668e2ea0324a7c0f6338b48
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:feeb5c5d560bcfa0914418f20a6a72fcb2f70104f6cdd0caceac792757807564
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:b7bb25c6f09cf75f4ec2fd7a8961ff728891684646a70fa5602d1c1853706686
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:82e6878ee77634ce0238e92e407d55c51076f05ac9f20ce92882e83e8688bcf0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:67d9b2130e3b4575930cc6b7028fd9a716b8fb0a53cdd9a42fd035a3d7d7135e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:2f893b0119bb21b22d3ea0bd64b33ad79f266fd5879e03ee2c50f4506cbc278b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:5b5038dfd829e7f3c57d5828f8acd51f14124e2d1b4b3b7aaf50094505fe5a4f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:7b1483718a87387db563f811c6365508a77ed49740caec6783ad94ee193d1bb1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:e9830b620348693ff4832bf448fabd4aec86c91a9adbd7a43b57b049b3db6d0e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:c2bf70c18884e0bec0b22fdcbcacad909053df7c02ab3fe50671b14cc6e9aed2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:aa4117d60348219061c452b6b5c3dd46704fa138a5d83cdb2121c5e1ea63ed9c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:d1272c87fb656e8826f45f7a714664d13da589ceca61c1b416d3d57a5dd26d8b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:13576c6197bc81676f68f6cfc68e837fe5e3b2daa081a6414bcf68caaf6e4c17