Sign inSign up
.NET

dhi.io/dotnet

.NET 9.x Runtime

CIS
linux/amd64
debian 13
Tags:

9, 9-debian, 9-debian13, 9.0, 9.0-debian, 9.0-debian13, 9.0.20, 9.0.20-debian, 9.0.20-debian13

Index digest:

sha256:199d12bb37b04a7f30448d3df1da5b22b13cc12cc8ea388b0139bb0f0340e30b

Manifest digest:

sha256:83422695752423bb037a610272743db35938584f799cdde21eb400d4b59a9c07

Size

51.11 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dotnet:9

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dotnet:9 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dotnet@sha256:ccf119d86eabeb16933474eaa96ea3b2864dddf0a36bf2d42f6bf480b42731e5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dotnet@sha256:a519ab2693c22c1e167f7ad39cc87962901af9475e3581c6cabcb75ee26b353d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dotnet@sha256:55fac8dac3b3f710b9ea2c53c2bbf941dbd0283ce5bf4356cc4c4bdc6db1c53c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dotnet@sha256:0e3dfe4818ed1a8c609d80a054023d7273e8b20444fcbe6c23780f2a181edb53
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dotnet@sha256:980bb599f1606a51950d73ca21aa8104c8b9970407f7403bd8fb07498afc35fe
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dotnet@sha256:e09e2c77db46d7e7ccb2186b7a5ced4f35d87395385a654007cad6d110e6f0b5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dotnet@sha256:ae6e61f4bbe5b99772f435e640805ee241fd36e0ac01e8a9e39bfc0203592f84
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dotnet@sha256:76cb2f9ed57bad6e9d7b161be1742e99ebf020f0000eede8578d5b315ffd7de3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dotnet@sha256:77c51faaa47d981237267c6090681ff95ca0065da5a698d34e5c679e0e2c5a93
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dotnet@sha256:63cd1eae4b49248e4df11e2dd0b07109021b575c0643dafa3ac9ebaf6fa1105c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dotnet@sha256:b34bd07e74edf7e7ac3cd2fd923091d074808ad454a5f73095831807c8a00e3e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dotnet@sha256:68f1bad670f7fdd3f0ce85b673fcd50191c874911b79703e8b499b4c053df622
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dotnet@sha256:44a4ea7c023f0656a7cfb70cd6be66191a5190f71a1912f0c2fbb18aa9cd96aa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dotnet@sha256:c2029a0c73ad57f941f93f38b3bf3002678ed4c18a6d06c9cbd3657041720a2a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dotnet@sha256:c825b1900109d966acbc1baad47c4f3fabf36b422f1521671e7a9bd9a1d154d1