Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x SDK

CIS
linux/amd64
debian 13
Tags:

8-sdk, 8-sdk-debian, 8-sdk-debian13, 8.0-sdk, 8.0-sdk-debian, 8.0-sdk-debian13, 8.0.425-sdk, 8.0.425-sdk-debian, 8.0.425-sdk-debian13

Index digest:

sha256:4ac96f821aeae64368c61efa1ed6e5bcbf560dbce7d469b63e8dd1c1d5c4e8ff

Manifest digest:

sha256:38935653aa54e14117e998ff80c404b4b28151e4e825dc7fa270ead6ca58d12e

Size

230.65 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:76c97e67c5ac572e14bfaa244597d4b1f2a7dbbfa3d08588f60f9d0b2a21a124
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:9ec303de336884777bfc75493dc76f009f137ee6fc5ba5eeae2d3d06e62a5c19
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:b67fe51bb8401217afeeaf658f6a015e4787f5bdfc2a8f745aea732b29878084
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:2228478d38728c6b399f364ee95023794b290bc1aaa18f3a4fe9cd60244a992c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:f4b0e44d8ed15f25b7c882b559544b333b8de6f31b0a0b193baa03e9fb74f209
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:253c03b08571f973456260633a06a8f70c1598b4292b8600a9cfbbceb6f25c36
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:c0b66dbc4f54994c4b730af8345962ad36b42b177f2c8957c1db767c736124b6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:839057988ce547648a7f5da6ecd43bc127187e66fda329e889eb38ad9f5a774b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:8207363a387622da1f51d9ea3b51df93d1b443ed13d7f3b52a96eedea3a2f891
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:d3f1c18938fe75781d379aa65185b68b91aee44ba36a808439419598541b281f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:128752d765786a75c92584d73f5728006f45ca752f3a21e002a1ee4b6ff04ec2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:900f6c559f451b413064a7a39702e9c66f4ab72addf213a9d8770c07f542ef6e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:6935d1c15774247156ed751812ff4f90a625570bd4d5806c2c37d5a47763bb25
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:29b295639d15236e573e9c7eb5b8d1bbb9b6993cf0998bf0dabe9e4d3616fd22
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:84c9b96da516b74ba31ee2e26062047952a12f222cb2b50dd513a4e9637c1cc8