Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x Runtime

CIS
linux/amd64
alpine 3.23
Tags:

9-alpine3.23, 9.0-alpine3.23, 9.0.20-alpine3.23

Index digest:

sha256:4aed4c3e7d60885119365c9036de24896f3ca2c79ac070329a15343805e74c41

Manifest digest:

sha256:133bb6cf977d320227fbb43815c65eac22deabfd7af33630ca9753b9fec0a5e7

Size

43.48 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:75686a7fef973258af643df6944356c3dba46f04eec0aa21ac0fa3685a7734ee
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:a2a31e906e86ec55f9a7d1e96e1bfe3853df174e633a7062666c51cc7c6e3399
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:2a67a2fe175497dd218b6214aa396ccf6ba419d2a055a069e978c9a5d72882d1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:fff2fe06426356a0e8c59edeb0ec5f9e9916cbfe3ae8942023d6b35508480f95
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:bfece9807b3302a21ad3d46a814f6225f0eeb0736b1effb5cd1d6b68222cdeeb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:fa41f44bce96a2f85f0aaee3c0a519286ba1c590e683bf710e89e447b34115e6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:791eefc66f3992bd2c8df1e311855633eab786e77cb5b98593b4d238af8c0b6e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:eb0a4299b13da1be88c1912eb6680e3a9f98bf79235fc1b30ca932aea6ec0298
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:778b6c1cc4d5e22d290475a6523f546b8bc19bb278fb9203af4e46ecf1ccfaca
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:ac3ea364a2ad52bf3416900ee08b245663d63e0cc29c3b63142c9e9f4929cd04
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:c6e2a24c1524123c7de7296ac432987aea0bf4787c28e9896b5c456ba5189d5e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:bd539dd6cc45d102e992c1e2993e14d925af5a00b24ed9adf8c48c0840351d2e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:7a073c7aaf88914bbcef83f311677ce95426a2c09523c8892bc6b9efe0b6bf60
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:b4d480828bfa3e9f79524991ee748621c6c3b9d9c204b31adf67e6024d1b8e9f