Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x SDK

CIS
linux/amd64
alpine 3.23
Tags:

8-sdk-alpine3.23, 8.0-sdk-alpine3.23, 8.0.131-sdk-alpine3.23

Index digest:

sha256:88b9bcb2073bd4c27b86a6017fea1a835d0a18dd9c3ebb081170dd87864aa86d

Manifest digest:

sha256:e25bccf28e13c2019422d806f771973d41a05e70278c1da823fb4950a6c68bed

Size

192.85 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-sdk-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-sdk-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:0561c35606708370e8cb8de83b67faf1488ab586c916e5fc78a482b5a1da177b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:069b5affc1d783da87cd7e0fc56d695efa7245eb4d3e73491d05038ad200d589
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:30812cc598cf79078f27c9ee04e2efe80367ea3fb68d9518fa0f0d716ad80711
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:3777f375b864159cf65f8ca87f4087a512f7e385bb776c43f82c3233dc3ecf93
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:18461b87204f587d50d5ea8341a74b2a2ba58d087f4bad93b064ac8edac0ad54
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:ff5feb80986ecd22b7f329bf63aae25c7b7ae3ee4143b45ab2266ff237ef5432
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:aca23b47697fcfc5cd0386aa2eae59b01e608c0ba5b82995d9f6173d4d7b5a4a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:bdac98d61999e4223f9968c326f333e413ea05559c5edb2f76b060fc6e296baf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:7e6a2241f121389f0c9d97558f37bcf7311cad47ff0496eff49d1506668208e9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:065d1fc93b249bb784657d46adeda181df1d237e6b8790cc3fd536b832e42667
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:1c73842004b98d41994a271f7aedef369ee2cfd93acf0e6ff46b03021e634609
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:d3ce678fe3548368b9a5fdce43b3a682089ede34bce57a80dfe15666ed3b82b8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:e8aa6c8b7d99c644e47141692f17e8fbc607cc3900ac8172715fb1eb34f56420
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:a31dbdf2fe062e02c2ddd63d3a9227569d9a071ce9a26bcfdd72e3ae89c88cde