Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x SDK

CIS
linux/amd64
alpine 3.24
Tags:

9-sdk-alpine, 9-sdk-alpine3.24, 9.0-sdk-alpine, 9.0-sdk-alpine3.24, 9.0.121-sdk-alpine, 9.0.121-sdk-alpine3.24

Index digest:

sha256:9f6cdd2d076ee85b7cfd993a3a43def3fd6836ae9b6cca23b8dfb09de80cce90

Manifest digest:

sha256:3ba03ca98712019a617c4e8b6f5da206620eefa764dc2f21682272fd36ce3afa

Size

187.58 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-sdk-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-sdk-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:5987f593766ecce14008ece545e9aa71a1710c0ad8b6192b6036e0227db99cf5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:cfa67186ad23153cefab72f0d4f9af7539aac2f29568997b78a9e0d9312f294f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:fd612755105b701b3db662b481ccde13529841c94fa0dc5924f261d81b1198e6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:87864ff238b62a1de20165cd7a3868d5da1128056d01be7f21fd6cd81ea64199
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:531bb6b9e5f85c3d5ca7c7fb68f9ca53a7d334c8134c5d0a343c0756ff4cde28
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:a380c6579b939889d6faa867a8946091d46d4a8574421c715644c2dacdc8ffe8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:009b49cc172989dac86e0160ea428e7ae748539e1da5f7ff3c88e876a1815405
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:6b8614e19de4883a5eaad24dd6d3f943092ea416e996985bd7764fad3fe9eea0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:a88cde67496f722edb4e1f574af839a2da0989d9bbef7016f2d3a81149e8745a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:8ab13e8e649404bad1e94ad761614cb32457e7e39010e50bc8e654a2631384bd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:9c068da876a6184f0631549029aade4b73a1217b36a0d9384ac3ce8099f82c9c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:a66b41a0cf7057c042a2f6118f983aa38b9f0d4bb26e760b1ca49ebb6f895b0d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:71737b01c53c25bd662260495efb9dd8b21ccb2c38110e328192b56bb3f7a5a0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:8bfa5f887bd5d8eaab84374800479addc64e6d0213aeb5eb04d66f2c47a5d0f4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:67e4f0097149d74fb071d5cb779acec732992b4c120d0a4bed4ab4fef7f76a15