Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine-dev, 1-alpine3.23-dev, 1.35-alpine-dev, 1.35-alpine3.23-dev, 1.35.8-alpine-dev, 1.35.8-alpine3.23-dev

Index digest:

sha256:649e217eaa650a8d1adf0c784d2ab804786cf15e6016d0d40ebd4d31df3ab771

Manifest digest:

sha256:8842095da895361c1b5931fbeebf43da483cb886e26729b2d283b13d812f5f81

Size

63.67 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:068d4e34499ea4b2b68edbd654fdc78f4b2221269ab093cb7a9c86b80cf7dfdc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:a620f9cd51dede8ffe4aeb1c7ed34e35cc764c1335de90084e2342e2f9884655
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:143c6b988c4beb9f4461d9cf43979d92bd41454e8cdebbe40e75d248fa198c5b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:0b026ed29ce415b338be3bec7c39a770890e58d24f6da972156547f987db408a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:02bf33e79534a7f8fcde82b1a98a944c220ae3caeeeb32d4e32c6718128c4ea0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:0a90ac2c955fa6fe501bd9ed81a189b1eb2dda2cd8b8852a548e45ed24be705e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:86a72b558372b55b0a1230d222cd9a980502961ed0156b3e8adc372ce4fac3fb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:b510b89cc84520dc9e58f0fdb541958ef503ddab3704b1926c2a452c3bc31162
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:b8e9e74e5a2c060d342b29d137fed11dbbaa85da3c903b62d371d3133c47f92b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:f948f431e605425ee5878b807fea8e44eb6c2c7da658b92133bdb95f1e61d3da
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:72aa0cbaea1f05df9ff37441c88698df5d4421e62bcbb7b92658471ef60eab4a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:700ee20bb10e81577603058eabe6f85ebb39c5fccc852eb80bedb598ea4cbeda
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:f4e562f57d2b65a2fca36b0d9c28f72f2bcadcbb027827e3e588eccc30f79caa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:3e3b68fe486f1aa4498d1205e8335632df1ed5e0686a6cc7dde40c256184e817
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:f464cd8e0abcdb1153a23e0b14d1b581aa7e5b29faec1928758cd7fe107dea2b