Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x SDK

CIS
linux/amd64
debian 13
Tags:

9-sdk, 9-sdk-debian, 9-sdk-debian13, 9.0-sdk, 9.0-sdk-debian, 9.0-sdk-debian13, 9.0.318-sdk, 9.0.318-sdk-debian, 9.0.318-sdk-debian13

Index digest:

sha256:bf6844ca120496e3f8a230038ea4336d0404a87c7b07d53ec3caea4a4edd55eb

Manifest digest:

sha256:6f1b3c275bf8e3113a43e2016b9ab73df2f5f2e22446a03692893ecdc05627eb

Size

231.77 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:28239f6516bc61acaed64dfd5b18e5498087b67aa923a359f4cd487c9e9600cd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:b0da45c8879143e8246b3839e0543a437199c8692273e78b8092e8816d1d045a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:f2c605708c331564de9e98a0dd09b35fe7342032335faf078d59b71c00b2d749
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:ab414729704dcc0365cd2dc1a40d7a79b087b66ee8f262e32a8a3f571db651a3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:576269d0155e4e1d8d82ceaee1fbc6a7903e01562a64a73b1134b8d272023752
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:b2a374c01ea6aeee95c7b699d95a08b2c02e39c85a92c9c6d0f096934784ed78
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:76fbae2f2c64ff012e71281f2a6f206fb755554ed692a2ee8b22357f6082f3be
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:ad3c6d9e760f5fe935fa3963a004b3e03986f423ff8244ef0ea8f283e3d110d3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:d241d79945b9734ee74c422f1ccda1c5c91fd8dd1850b12c31a2a835e1f82d68
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:809f41fc7801ad9e4a9e00fb0b6604bcb271461a3a7855e4e55e3babaef266ea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:f2d7f71a93313a4cf06e38f91619023d4e12dc67b74158cb85f18be7b18c4bf6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:1cdbee162661c0c073e303dddf2a5158d742b4b03e82c014f31c039795d31b35
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:efc5866238d04a783e80da6e316fa3923df5f120e4cb9615290419381090da49
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:eef1e16699de033427b58686766a7e9fc03138b890d5c78505807d53884fe940
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:50e424ae9e8e8538fe1b3d46baa67da54a4f549e7c7ae8645c5f8ab660558e69