Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x SDK

CIS
linux/amd64
debian 13
Tags:

9-sdk, 9-sdk-debian, 9-sdk-debian13, 9.0-sdk, 9.0-sdk-debian, 9.0-sdk-debian13, 9.0.318-sdk, 9.0.318-sdk-debian, 9.0.318-sdk-debian13

Index digest:

sha256:921fc69b2f8e9f5509ec6bef2598e7c6b73b57ae769910833624aeda83d65371

Manifest digest:

sha256:4b2804f291d8bdbe3244ff61e97730d5f56a5fbff018c37d06d9877818a4803c

Size

231.75 MB

Last pushed

6 days ago

Vulnerabilities

0
1
1
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:15b34b0d75184c603c9d9fe1e25874b287704d5a4a67d22387ef9376f46f0e4e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:cbb751393ff8943387981d6bf587075db6f508443fb5267b6c6b75b520a02737
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:be4439b2ba05494d31bd109f27a189b754f41d66ce3a9dbbad707b8c591e3cd8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:65b84561bdd8b9003e21f061b9a6d95f400a5172dafc00621026836a45544f6b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:8b09ec065ca179907e63388920e6344fd523a3c22c1f08b62748c1f1ece92045
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:8fd2f07f671910a6c33ad993cf776e52a7af656d28a64da904caa611eae13fc8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:ed61d0e5ccc7ed9ef01dd0d044ab33309a91083301e87723aa98ebb27d6a4c71
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:3a582c97fc660acf3093ed82a72ef9017f7f066b99b5c906349c14e5ed7c9fd5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:9029f656b0c3e0b6f73e5b0394cf005f25108e491e00d53f62eab757e71ba6ac
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:ec17b53d0b4f8b514524c717bb0fbcc9d52469e65cd9ee94f3a8da78cd2d6520
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:fdcb523b09a1fb54a54fe3b4dc08640deba934acbe14ea88f3f182708e017038
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:4218e4a68261870118fd5b3e3d88d6fb1564194ad9a26b236e36f7d5142c773e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:d80bb22fe02898f1959847475701e500a31039368731e98d2792496cab4301ef
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:1f168124ec5fd87c190e6cb8785879918b6536d641cfadc0c6baa5e25916d681
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:80c2fe015ca6bd2f17fd8f061d1573d2dfa1d026aaae65e98126c9862ec2b1e5