Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.34.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

1.34-alpine-dev, 1.34-alpine3.23-dev, 1.34.11-alpine-dev, 1.34.11-alpine3.23-dev

Index digest:

sha256:9c898c1492f645e1a697cd19df2386b8f8e429f15a7b26cbfcd3e6e821186877

Manifest digest:

sha256:cc75fef64de6b78c0a00ca38f15c8bfb328b16302a065edef36e1ad7797715b5

Size

65.06 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Oct 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.34-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.34-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:e419cbc6bbeb2564f5c6f3653f4c9ab3852686690137bca1214996ce9c6174cf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:b9e00ef5bbc4f341b5b480a55489b4455a6c06d214d057f0d2db596e525baafe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:a4653ada44733f96c757c2852239d9b683834d4bddde944bfed0d80a1facdbd6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:79715a46fe04a565c4a0b5699ae6fe988d3b9fd94b270e97b156fa487c9625f8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:3f0847c41bcc09cb7c4c5e472d210089b1cc30437557f4a391cb14cbe9328d15
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:c8df61423055d859b289fe10a4ce059cb777a0e1efe9a5e698df71542bc7e561
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:d2a89b5e1c6301944b2a2e5594c82dbd3b26e1e0c3a1d37f028cb1db55e1005e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:d5c844a759a1ea08f78ee10b49db4c3f15ed04a1abf04d36a899ecff57b4a816
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:99569c5c472bf2ca01d0ab6246e426db345d07560565778ae2bb0503a11fa269
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:0afaa4c8e93fba63862be9c46805deb735f6467192016d507026358a92d7d204
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:9776d3ea09f1e3e4d43c89df9694c351d27c83de4b5258780b59eae3559018fc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:724473a76ec34b6243cd23e1e131173e861ec3d028c2c34ef5bd83e05df0c4ea
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:6d4f67e590a70972a3bacae7e433ca937048b7d7a5dde7e55b70c15739ecb654
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:24854f98725528e66f27df02b2b32be03d8d9993c49f2f289a40f6c2feda185a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:c760f275648ce0df109854e5d7b87c52fa2672cd16bd2e4a511fb51929fb3604