Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x Runtime

CIS
linux/amd64
alpine 3.24
Tags:

8-alpine, 8-alpine3.24, 8.0-alpine, 8.0-alpine3.24, 8.0.31-alpine, 8.0.31-alpine3.24

Index digest:

sha256:f7f2296156bf1bbbb2c999f4b1027f2f7cca0f5b1ae8c0d32740b1cad106b638

Manifest digest:

sha256:c20963444a9683eba358dfa36a44c233814ed6d7b70af5457ac35431d9d3f3db

Size

42.35 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:dbf36e655affa1c3de2f99a2123f9153936ba3cf1327e85369d227480f9f87bd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:f43a56fe593c721477df8feaef7e609c62a97d46dc2f864a784be69913379331
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:7892e01098a6aa6b2a679028eb2a450f8fdf6b411fdf7f840af7a5bc60a0526f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:e7419edd6894814129731eadcae8ca1129e2a3b99fe5d33c1238bfc42e3db52c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:28f8534f91aa539ae35cc2afc38298fc3724fe768afa8de2816eb529a2747812
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:0dd85dbeeb0ca6c33ce5a95907f9ebbf745fa6a67cf50321121b160d7e0bc782
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:0908693a5bec12057fa539e6fb8ce6eabb6fa5a949e58b668590ae540de3a3b0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:85935ee9abdd2213512a4f9b5531b0f8e0828b6bd8c1e25a7841641d540feb31
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:d7354465778e44edf68f8fdc4bb1bb3da0dee4ffe9e60b3948370531681be4aa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:99a539256266788444ab6d4932a1e1d5d868a902e562aa5dddb969b03209e658
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:1125145d376cb095d63ac34d28309441fb1bb07d91911a2fbf441b280fe2c7ee
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:30e438f2c40673f878d6d7c278b6a26620db1c894ec20bb87f8715111ba08462
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:9350e39af410ea32d9045f6bdc2f7517e0bb29487fd7f35871434e26da5a74dd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:627ec2f68a90596e4d333919b231e9af77f4aaad02de06967c01c784786bf78a