Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x Runtime

CIS
linux/amd64
alpine 3.23
Tags:

8-alpine3.23, 8.0-alpine3.23, 8.0.31-alpine3.23

Index digest:

sha256:c880961fc579aa34955b836385ab317b3d6499cef15aee07a340ae27ff4a073e

Manifest digest:

sha256:e0e9c983a84efe3e3ee0de7f37a2321b174e14ecb0fc70747531eafeab065968

Size

41.95 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:0fc5841e9bd8ed26e17757855c50ae76301e962bda803904cc5ec919d99f0289
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:e0de72b7f351548a246bc39f783ae9979a5c3cc366d6ae78afb1eafd3bfc958d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:ced89af1fd33476c42fb50e261b1c44d76971337b47fd9ae796826adb6bdf092
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:0e5dbf850cc5f52179dfeaf2b78ee6b6d253a87f4991d23fdbf8b1cd2d12a837
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:d04610806b4a0ac63ea293bea24c36cde87998d5080636bde58e7e5d03e5d349
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:2bc7be2ef607adde1b2da9ba678d6ccdf9f32b366f0688328d10c941a1649064
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:6b4bb4f58fdd8cc4baf7e904989d3962b7133a1834d3289240b9ef8b89fa5735
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:967c661def85572f43d4c35367c154bcf8af80e32b1b686e32256f5d12d41a79
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:be26601c204d2b9ec6dedda8a62d6925470846bcafb2dc7b3f4814fffb22efe1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:3d7cd74172fb94fdb6583015131fe2c00cc99253393de192d392622297fc07c2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:d7895c244a11d66ff034596c218b7e4956e361be016928d2ae6dfe754392dce3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:c0433bba3aed36be0f3cc690d5be22bb07ac8fac14a6b0fdb7ab7a1dfdd317fa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:8fa1bfe635377fab2f1d2ba261188fc09f7e06a8536fd16961543cc317f43eec
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:367e21e1f346e8613d55e9fb608fc6e613a5d71aadde9953ad985d79f9646e75