Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x SDK

CIS
linux/amd64
alpine 3.24
Tags:

8-sdk-alpine, 8-sdk-alpine3.24, 8.0-sdk-alpine, 8.0-sdk-alpine3.24, 8.0.131-sdk-alpine, 8.0.131-sdk-alpine3.24

Index digest:

sha256:8d11b8353a661e51f084c888e33658807db6740ff2e1a0fbce4d0ef34d0bd1e4

Manifest digest:

sha256:38f967eef7bf81072082b703456d3291009918416dc9cef2503449a3f8af974b

Size

193.29 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-sdk-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-sdk-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:1eecbc187cdb2373124b28be77029b02dfecb528856844c8c394212f33f6db07
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:cfe03231c1ad6686222afcc6724921e6188489ccf4d6240b647c48b94785a76d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:8644930cd6ae4e4e45534f0c2ad19d4126219894a9e80fdcac47edacbcab4f47
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:fa22c258d4fcf2e798c2a63bebc18e226092d7d0f199c313f00053d41a4c904d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:e72db713adf1aa252a0e78968d88e6fadd3abca5d899d59b1a6d4a10c975cdc4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:f9eb8ae53ae21d8929f292ae518aba4b5f28130c623ca8cc6e7b6b40531c74fc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:a0701077687a89cc47ab9069714663a3f22e8e3d85e3f1aa72050294796aef09
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:680075dc743c20a115d39679345e2b58129a657c2cbe35367ac8c3391b55dc96
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:96cca78a0379e9396623d60a1bb72ff2c859a23c81ed3b37006a78a7951a4e17
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:aefdaa11329bd6778eccdd5ed70871cde24b459e0f078a29e46a0d9cce7a0164
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:f22c7e0e6178538c14fc0f307afb437341dceb2d737fdeaf657bb9793f238bb8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:3762164d26dd8db5e57d5d1c83899e68b41762382a16d1fdcca069b184a701da
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:ddf4b6337ac48a513767b567689a3e6908f14989d460cd6a7ca3ca20747b8e8c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:704a492009a541b6547b3f8d645ef08ec405e911c3d46ebd3fb2589279f42fe5