Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x SDK

CIS
linux/amd64
debian 13
Tags:

8-sdk, 8-sdk-debian, 8-sdk-debian13, 8.0-sdk, 8.0-sdk-debian, 8.0-sdk-debian13, 8.0.424-sdk, 8.0.424-sdk-debian, 8.0.424-sdk-debian13

Index digest:

sha256:de5197b7c3589d8c6421b857c949666102945b026c5a8741131c1e00ef510e22

Manifest digest:

sha256:70f985d6cfcdd1af7caabd643844c49337128c56744456692103d631fa73c7f1

Size

230.68 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:d06a1ed06f45bde98bf01eb1fd44497fdca3c5df96c0aba18c7ba2dbf9088c66
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:61a33d359e244170f887e8f3299472a4eeb0466960ac1d711e09bdc182170d81
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:f7d41120a25475162e21129679035eaecc3c6fd29af1ca3d1fe1135b89ee3b10
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:70e51bbe3af863d741433a75603c6ddfee7156a6f0f15ff98fe1d2ad276e8627
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:b5b32f052af0367c10134710660fc875104191bab7019e90f4c48ffc534f79ca
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:3e96b9c6d2160265149d8e2dd51d8b229a871835eefb5f3eaeb35b0da9b69f5f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:0ce5ab73c2e974aae387ee5a4e636d7f6fe1376b5a029a526df77705654246ba
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:819bd74a1e9e12dd3ebc67998daf9eda1da9ddc0c7d8200adbb6866ca8292cf4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:2dbe2d695e139ae5746e0caee2bc82c8a522f89a5f16b0a6620b76d300132be4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:3424792763cfd55d7cb8f815fe281a4da436bb7aba022e16c4c73bd284654e54
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:cad5b34e5e72512483ce8b6b0b1ac05bf593775978642adc59acd3ac305b5725
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:8453248aa80aba800609681bb46b0e1e72f91d9225813eb366a2d854b09728d9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:b4e05f20aeb919bdf276331404731df13d54f9bab354080b870e2a821b9fca52
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:3476c9472e631f63ed8e5afedd63a69951d23140d2c81250fd1f6fc24862ee3d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:3c822d41b0958a06eeeaa9ce80cd4f70576278824bad963cf94c205ac0c8753c