Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x SDK

CIS
linux/amd64
debian 13
Tags:

8-sdk, 8-sdk-debian, 8-sdk-debian13, 8.0-sdk, 8.0-sdk-debian, 8.0-sdk-debian13, 8.0.425-sdk, 8.0.425-sdk-debian, 8.0.425-sdk-debian13

Index digest:

sha256:cc8113582f0d9b9a49c4803a7331e646028815b50b408b0f9716feffadf96d1e

Manifest digest:

sha256:238ae2cade2e61c0615dfdd416ff1857a343321e9e89de3b656b6f5c24ace8e8

Size

230.65 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:7ab009bd2047e04e805ff544b5365958f138b77a2ee00dc0228a6e088ba7874b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:894be2f561fe42e39d70ff2b328efd2d39665d998fe638e402699b5b2723318d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:47062324919f4a1e2b8b8b8b09b5f4a9814d66d83f7ba91c19275a0e20e387bf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:12eee893c0379a34fe170f9772f046dab5bd577ef446dc47e5f63e5e0744764c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:b22a42f82ea07666273f77f9db9918f1de4c8da04c16d0c2eb9bc55922dc69cc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:81a2807fa43f33457d19d7001b5e52d00eddca8c7c3894882e7c1ce84103e3ed
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:fbe1f0ad632f0c5a9d454d4edd1b6bd7311a3b046e6d4f7a016f69132c1ccc64
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:ae3209e5145dfc1ad082b37cedf2148c03dd61eee4e5253de18416b1e30ace77
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:0b8d38e553f48af01d5a41b214e263a7b95b0b340eea31ff5c446db677e5591e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:29a966bc2e18d8f02cc1586f03a06929a89c5eff7715db948f7b9689c9f72eb8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:3cb4ba68cb1ac498b5838ffb79fb26176037992cabfdd1edee325412ceaecddb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:d5d318f6811f7d52f38218e8f7d7fb6b28395aba4402a3d2d78d7179456767e1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:a412fce0509d32e8730b5619506c949768195f54f4ea35b475396dfd6b7f405e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:d95eeeeb2be083ed2eceb73fb9c994cfd039ed7d582ed9b76604b3c189a19f6e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:41d884951f6f2f929dfabb28f9864ba2e7c82c97a78ac82bd1e40321100e5b5f