Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x SDK

CIS
linux/amd64
alpine 3.23
Tags:

8-sdk-alpine3.23, 8.0-sdk-alpine3.23, 8.0.129-sdk-alpine3.23

Index digest:

sha256:9f8e582460f39ae7974403f6ab3d75fac7c18788e8bd820fd8d76b267ace8e13

Manifest digest:

sha256:598d4da29b5b7ca0cf9c22c32589f45e325aa4df355fc0b622e901850bd2abdf

Size

192.85 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-sdk-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-sdk-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:5811edc60c7d7b5fef2488216139542d80c6ac4b82f07cd1581318e0c36197b1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:a37d039d5d3567be3071d27f7b0d569d636b1ad68e919000a73d4e7a9eae79dd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:2776c0a77c66fedb5410f4ea9462a36d67a2e2ba9ea1287c5ef44646b085a60a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:f2f3fadcb92f4e56cf93d222c54db6a1af015afe5140710b5b46e287dc779a6e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:d99c3e393de836ae620b927b1ce63bf80601721cfe393a2839f0e7d4db40fa8b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:3d47420cd2bb56fbb940d36405a2d25f53e086a359e1889c80aa10fd7d253f4d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:60b26cc9bc8926fa54ad9132980c1e200598d0f5ec714207132dfc68c2c35ce7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:2c845b409dac8f32c2dbfaadf1cbd21adc655ef22f46e8e56f80f14346f4dff7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:ee0921f1a249db74f0de418959cd403cd0ea5d642867dc967f8b23f0747a9e69
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:cee1403af40e51ec5af82b950fb03a2539765e4980c3c47954e114562049d1c1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:293da18adc0948bf2dd4e8bdf2d534e9e194d6528550eb1259f3c40f7bbd3025
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:21ece00e1c41e9003885dd44dd36b7f1b061c18dae2998f3b9dd3111358f8e28
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:b66dcccf1377e8b81378ae1e7bf23db7f570220214f0022fc579b822b9490638
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:e2947df74580d13411ba5c9fd0a8f7a602299f09b3adbae18e52cb17fbb86857