Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x Runtime

CIS
linux/amd64
debian 13
Tags:

9, 9-debian, 9-debian13, 9.0, 9.0-debian, 9.0-debian13, 9.0.20, 9.0.20-debian, 9.0.20-debian13

Index digest:

sha256:ba68b37f8e2521ece23b047af4745d50551d506c00c2e714f30d2c7f11fb5260

Manifest digest:

sha256:6e45b2ee4c1c48251edc9ae5cc86c96a3a3267d923f15d801ecdb15835f20250

Size

51.11 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:2dd19a31d4bbcdf19161ff583e925f92f05e0452b757a37089a555f9921d6973
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:269108a58e5dd01842ccb7dc65037e5a6e932ef81bb392e4a9bbd24a6098e87e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:773c7b292c08661ae9dab6f7ef6e5871fb44b463d27633caed9f9a236fc98e48
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:9cf8c78c48a3254221c9c52e284174d49ca687696e6c09b408dc79111558efda
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:4e45cce048eb9d0070abdd3bd162cc0dbf1035d360276a3c72adca2d6428a031
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:e9606a3259b1a2c2a6ab8e2a4622975869f40ba80cabc125053fb73664d262e2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:b82f09d3dacaed08e89c386246014c9cc858e68d9a460b215ba286f0c5edde02
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:0cef43ab6b4f197b396b0f202b0c16478ff006598e45e4ae5f33177824bc30ab
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:1dee97a99892836dd3832f1fe907df4b96e3d23d7a9a9ce5b9482964496a322b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:ecb541d786842a0ce0d824974c06e59fcb93840bc62abed7159874fe58e621b0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:99e3da0f4bf0be291241a5e292845a16dc2f5c1a7d6804c59ab4fb8570707843
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:874932a3d2766d002765c89b0c62d50209ebc9c7c147d35b02544a21f019c4b5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:144338969d94c16b12895cff998d077d0beca6bf1ee210dc52e897da110040ef
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:a6e9a4bda1d82782ef06012132e8c85120c54e323bcb324090c09def3013baee
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:be67d1479b1b99b743adf886769b243c86ce31230825d12bd2a45dae3281014f