Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x SDK

CIS
linux/amd64
debian 13
Tags:

8-sdk, 8-sdk-debian, 8-sdk-debian13, 8.0-sdk, 8.0-sdk-debian, 8.0-sdk-debian13, 8.0.424-sdk, 8.0.424-sdk-debian, 8.0.424-sdk-debian13

Index digest:

sha256:f0530b02082f9c57b9f5dbaddcac40b3b6ae9358919c57368366e8d47a59d747

Manifest digest:

sha256:c60bbaea28b01825bd908d720a57113fbf66ba35b34a090165e5117ef4a5990a

Size

230.68 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:db4ae2c6a395aa295c3986ca5c92db92f8942db8a462086b17e90ed92ace3fed
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:01ac01911188ccaa840527124f32b83a65954bac7fe1c3e87a5a00ff276ee316
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:2f335f4e9b4ea23917e559d0c7faf37da5ba31d6d015e308457716a713d847de
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:8c8f69c86e8f09f55c9bcf516423c0b76f3105ccb00cc8f9660835d3f75d6b6c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:fc02f3accdbe98378d276a8f576ed02dc8bdeec78968ed3751146e9790ef1e9f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:ac35328cc67549917d8f88dc927188bb6a5c5729acd0de235e301a83eb8d3fa1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:658450ad192a8488207def59830a4c6a748c65ec37d79beb3fb22486066fe71f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:13e5110ef44b1334cbcb936e6f2c3769bfbb0b6f3f08eb1574a59cc9f88b77fe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:16809a0a94bf4540d3441d1c01061bdb2a8d95d9b1e44c9d20a1ccfe5f25082f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:8cb04541ffe9c193b790e8ecb5cf66ec17498cc71bfd39f0fbfe35a9245984b4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:0203b5ae1eac8d13c4aa88e4f3f184403458aa74ea36f735f49055aaa475b75b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:ef40c255b62893894a14921780eaccac02ebe2e4707c69f6b26c26fb8a8ece7e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:2801904ddb57cbe2640bb9bd0c8c1209ef75b6b4e50d7a9eabef5056a6708956
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:811e41c76fbcf74a8a301baf5a8320754462fa3361c0e31c21cce1eae09bffd3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:841111d33bac1bae5c54151a0f0b2b0a80166084266e51e05763361544950120