Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x SDK

CIS
linux/amd64
debian 13
Tags:

9-sdk, 9-sdk-debian, 9-sdk-debian13, 9.0-sdk, 9.0-sdk-debian, 9.0-sdk-debian13, 9.0.317-sdk, 9.0.317-sdk-debian, 9.0.317-sdk-debian13

Index digest:

sha256:9e0a7bf4e2e9686f6487bb959a26b0e9c18a74f74c4fef47ad8694e4c117ecb3

Manifest digest:

sha256:c01d2bff9ddcd4591d59fdc79fb659e5236fea196a924c66924e3c14b1231896

Size

231.77 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:394905bf24c93c0175ad9748f14e3b0de5be1ab823088293ee60a0ab0b0e1f2a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:9de78d1ea947cc6697600ce73a6deaff97a86327f12fd36861084afaa4f3e9d2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:6af1ca68eb6a83ab271a4373872bba6b6314676434704d8950730d843015bfd2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:601be61863207923bca30bffd2ec8e57067d876e6b03b2f689be9999cf37a151
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:ea75e6b4dc0be2659f9dacd66f77f8b1fa6866730203d47a18cda99011d1abdd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:088ee068544ec66db32c60b4fe8c869c03a2bd3f7af57d7539c2c0f55ff9579b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:a288435728558704e31c3a88fba440a5bf8037ed4e33b92e7aebc3ef76b1de6a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:7d855cd8511a1c6a5a03288b7f483502c97ddb563239eff763a5f99d3d39d993
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:dc3f238ab48e770e71f3d8cff4727d15e6b77130d4d4166a83d515959fd86cea
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:a8c5ec746d0f073f7cfbc137cd337fe1960686999bb0f907755c9f6c5a066848
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:94636bd66b70d359f38b34e487259230f2e0064526081def60ed33c3173a47bf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:854c2bf1a2aab038c5ff8b52b240defe523fdaf5c5f54fa7fd1df4d576427a29
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:784514f2eaee5f6dccc3fbcac0191fbc7951a84c2039e948238efc8a9b17de48
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:777f65dce26fc4bf6c91b5296d5a9ad8519c9cc9c260e5a044f78d6995281104
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:6a1c23b7f2eab7341007e3e3388f5289cf2149a61e48d7ed8601256c92dc8a5f