Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x SDK

CIS
linux/amd64
debian 13
Tags:

8-sdk, 8-sdk-debian, 8-sdk-debian13, 8.0-sdk, 8.0-sdk-debian, 8.0-sdk-debian13, 8.0.425-sdk, 8.0.425-sdk-debian, 8.0.425-sdk-debian13

Index digest:

sha256:329cb98c2d26352b19abedcc213f6e98043f50f242520f7489e14b00d42b2543

Manifest digest:

sha256:8a94f67fe7b8e6134b766e6f11127b1e72211fb755072e949381f19d27a4c1a7

Size

230.63 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:bebfedcafeb0d517984d7a183ea49cac9c9d022593f9fca9d2ce78f1c45b44a6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:aa99b7c24add41cd7a866abd16a66df900b33ef1501afff27ccfe9c79bb415a4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:0b769001de814f118b973b8f8e8ff478448abad7c55928746a8b0546c04e7474
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:0b5d23ed0fc1f461ba021356402f8cc0cc3c160808555dd47d39abf76d56bfd2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:bca9a571f43853da913f3e3d98ccc1f6ff3a39be6204a2d18d3aed88a6b4711f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:28d48e14ce542fae0bb890665cf85663bfcec7f05bbfa09a01a795a1541fe195
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:da7904d65aba74d0b3a956a195d16159541d14b6c975dc20167fc36b08845408
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:8af8c9b0938208ec04179bc6d7166f985091f6b708b439bd9881fb5e47b0fcc2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:7268e00cfdc029b8033e22978bda22bae47c5c0b813e277cc75e0a99a1d87447
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:611438c35182dbcf575b72358f128ff26a1121272260e59c2e9c5ee910bfcb27
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:8ce65c8d4fd534db0510cd62f8961d2a46a640a8c62d6bab9cd80a66c62770f8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:4d67ed29a7a72e96e1e87613fbcbcdd98fbf6e126dd58d626c592eb287e7da1d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:265f1876b055592c892431f405730cfa48f4ca11013e8222806f9bc22f450692
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:731ebf434dad553b7e9532db15b46816533af1fca5cc24f8ec06aaba6cf8f12f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:fafcd393c96782de3d61f7ff9659c918dda6916b19109f9bc2ce066a53885f2a