Sign inSign up
.NET

dhi.io/dotnet

.NET 8.x Runtime

CIS
linux/amd64
debian 13
Tags:

8, 8-debian, 8-debian13, 8.0, 8.0-debian, 8.0-debian13, 8.0.31, 8.0.31-debian, 8.0.31-debian13

Index digest:

sha256:7e6e8ecafb46a9f2615f17290d00d09670005243b9efc24d35fd15d1d140b60d

Manifest digest:

sha256:542f3dd1b7a729606c170f765f453803bbbf475ee5842dd986acda8d3fe0daff

Size

49.36 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:8

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:8 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:43b3df842087a6c740489439073b7a78802e149a8efcacba877da189db7ba931
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:8e1f68e76b4a523c5f8ce9207772023b9c28c23f22e421683aa50b7f752c8196
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:c686a8f4c8ba615456e9849bcbaead1a8a90a2b2871fc1f5bf509c3741bbc4cf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:358641524f306afaf819183f9ab861e6a4dc5fa4432f748a7bc7025848d32bc6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:55fc04ac90c584e22628b332a6659882cb86a328a6c24a539c2e0ae39cd03187
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:4594862e6f01e5ff1e45f14478ade9192ae5083cb96768768c07939d4e937e58
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:36f4741614bc1f0e280cd885888b2ce64638d39afad2ab4acdd18b3635c53fca
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:802f8bd88fff1a1a691e5700ce33088d524c304e0da756216d7058d6700fb390
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:8ccb44db0023db8fa207bea42e33bd6985390a548a14bd9a68b9a153000fe7f8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:608cfe85318a51ebee41936662204bc0c0ace85020d041489906a3784070b450
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:cd4530660018e12ce45992f82a6a2588b4ba109b96778b71674e606d40786307
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:8332301c994a100c6e4a31cb435b2818d26eb9c6436ee04b237396f9d2c1bb6e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:9296abaafda6e5ed60847608ceaa2ed2cab02b9934627737860c7adb1969ad1b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:1a83c4fc31efd482655506d060b6ab58ae9b9b0cf44b7e08c3f79bbb7ef894da
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:47d0f15911b06dae0d6cc0a684c4436bc6e852ccea59832e56000b363806ec36