Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x SDK

CIS
linux/amd64
debian 13
Tags:

9-sdk, 9-sdk-debian, 9-sdk-debian13, 9.0-sdk, 9.0-sdk-debian, 9.0-sdk-debian13, 9.0.317-sdk, 9.0.317-sdk-debian, 9.0.317-sdk-debian13

Index digest:

sha256:9e0a7bf4e2e9686f6487bb959a26b0e9c18a74f74c4fef47ad8694e4c117ecb3

Manifest digest:

sha256:c01d2bff9ddcd4591d59fdc79fb659e5236fea196a924c66924e3c14b1231896

Size

231.77 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9-sdk

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9-sdk --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:394905bf24c93c0175ad9748f14e3b0de5be1ab823088293ee60a0ab0b0e1f2a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:692e33930ff346db72fcb618647352998080654f831b30658ef91ffca95e1921
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:fe30d86005c029f07ee866f06ac15d59c3454d1bbecf958f92ea064848bdc5ae
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:1f26f3b065bd2d625e30ccafb5d5a4dc48f6aa394eb23b6d57e02d3238a941c9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:dbb0dd1de7166dcd8e1fc64ac007175d91b9949b9b6dd76611a382519a86c1b6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:088ee068544ec66db32c60b4fe8c869c03a2bd3f7af57d7539c2c0f55ff9579b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:a288435728558704e31c3a88fba440a5bf8037ed4e33b92e7aebc3ef76b1de6a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:7d855cd8511a1c6a5a03288b7f483502c97ddb563239eff763a5f99d3d39d993
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:c6ac106bc8cfc4b0569202d54ae7ec298e7ecf1f74102ee4011a3d7355bd688c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:c3551e458f3d316134bcf2e98b661165ac512ffded5a00bce1f162470eff085f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:f84d05681941b0b3cb944f05c670bb4c5d761aa26135347991aa45d4247e7b40
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:854c2bf1a2aab038c5ff8b52b240defe523fdaf5c5f54fa7fd1df4d576427a29
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:784514f2eaee5f6dccc3fbcac0191fbc7951a84c2039e948238efc8a9b17de48
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:777f65dce26fc4bf6c91b5296d5a9ad8519c9cc9c260e5a044f78d6995281104
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:6a1c23b7f2eab7341007e3e3388f5289cf2149a61e48d7ed8601256c92dc8a5f