Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x SDK

CIS
linux/amd64
alpine 3.24
Tags:

8-sdk-alpine, 8-sdk-alpine3.24, 8.0-sdk-alpine, 8.0-sdk-alpine3.24, 8.0.131-sdk-alpine, 8.0.131-sdk-alpine3.24

Index digest:

sha256:818a6333884d4d13df9570fd982e72f00fc34b7bb0e04dddfeffbab9e346be50

Manifest digest:

sha256:34f92bea81cd5f14fa8a35d16795c7723717c2e54f30c10d863c6a5c65279a62

Size

193.29 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-sdk-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-sdk-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:4b2411c1c15229d99f034e208f9649970086d56e92ce243132c6c93d1029c69a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:de9a8c2cae736fad9a0e9c1889f4fc3c46a3bd1add69c71c4931bac4c93a8453
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:4f1a2fdf35f3ca88022fd0fcea1d565fd65d669f48a6472412bf98f552c7b140
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:77abf016de9f6579243cef13bf58e8bb647ad43d90f911b1beb8cc4e09a48fe3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:b11d3fb335754cfb2d93a6fae7e879595507584c0f591464272fd20ff213468a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:b8b77d1b43ae5f71bb5363345991370d1fe622472f9067e681eaa5bf0b42c593
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:7440e2720b75eaa5906709db753a196615a6d69613f99f4b62f77e8bd66df9a4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:5d4920e47daae8baf4b726e672ef0ff32d97f2ab68f111d99718e923bebbe4a6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:a54cf70135bfeca7ed15172d04db7ef570bc43f8e747c8cffaec90137082c435
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:83cff6a6779839a45506ae21754047de50d4730baaa3b3af10840b85fa470d6b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:f2462e0b4e2c24f73c14ff8d26763c2ad80e7a11f9edfb52806d5f8e291509a5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:d1bc029236a32f616b2f03200e34cb2fb4583924bad47f96623ac300f89132fd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:eda498071fd033ce9cc2af14d43f23e22ff01cdf927ac348aa7498c5aaaa0941
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:7fff8c355561ec2673f16d4c793e8d83994e6bdeb0b361227dab85405ea46c0c