Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x SDK

CIS
linux/amd64
alpine 3.24
Tags:

9-sdk-alpine, 9-sdk-alpine3.24, 9.0-sdk-alpine, 9.0-sdk-alpine3.24, 9.0.121-sdk-alpine, 9.0.121-sdk-alpine3.24

Index digest:

sha256:570b7f345b6f747a846d5a3795900283751766fef94729dbf0b207b4798247fb

Manifest digest:

sha256:17be0517d23ff07175a996782361a6807977e0d4a2f84ebe66c572b373ab7a55

Size

187.59 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-sdk-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-sdk-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:bd9ff9ec4790713b05f4963c3f2542450ca3e446bbdc9be94b6279ba3e103d22
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:8008dd0e455a3957ca186e8c75958dbab79f6e8c8fb039c28ecf9ab6d5d585ff
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:a336abc7e3e7f0c691212888a88c239117e8e37948396f81782689c1af1264a1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:c0985d42a429801f94fd4210d57b70ff050c1b5d9172c653837d472eac79f5de
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:c994b9613217c8afca4ee3c73d512f88ef69e865cbeee2644afc76cf4f95f196
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:b02c12ac47792bcdf35f48e6183f11b2fbcd82db42d43b39d5059b6e0dbf9f8d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:f06696be64795e1fa1c90d869afc1e1c17a271cea03cb1c1ab8662d0da325dfb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:56ef5c813dbe6f7b77168287ba0369052cbd0d174e75fb55ac9409dfaa125aa7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:1424a149c1bff995ee56ee57d207a56793d927655da1693863b8e0aa4a014f3e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:2eccd83bc9cddf546d416fc4079e0c608ad1dce4b2aecfb9e93c54e812512ebc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:3be6a59cc58ed6c7e1887cf8ef880550b5e7d18d20b88dfb2ee5f555c0350ece
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:9bbb30db6787818b9d38ed442565067f0f7110d9ea3fbec780da36344cac61ae
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:7dcf3c8d7bf66713260af7bce75e07ef31762efacb11e5e567d1e44140d17500
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:c5a6236a8ad6ce97d443deebb23c55d8c979e88e92e4c0eab470278257228300
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:f2d8a05a8edd03dd0a54d82173b88e82eab2ac2435dca4acf328e4e8aa6aefe4