Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine-fips-dev, 1-alpine3.23-fips-dev, 1.35-alpine-fips-dev, 1.35-alpine3.23-fips-dev, 1.35.8-alpine-fips-dev, 1.35.8-alpine3.23-fips-dev

Index digest:

sha256:14bd9b6b7dc77128be61756ee189216cda9fc936c76ee38cd3ed722cc94c9da8

Manifest digest:

sha256:a1f792127a3c8e558d907d4ed21f4fcc42a81a61ec562f85b1d0835efb6e77e9

Size

64.69 MB

Last pushed

3 days ago

Vulnerabilities

0
0
1
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:8249523aa65bd0a0086f39c239573cb2906a64a9c8743edc0b480e7b998b7ce4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:e24fe848de020ee373e4bca2a9c3f5d514248799348be07eb6c275d6b92058cf
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:3124cb23cf9b3e53759060c9fa6614bce7b69ad2b54f63622e972b97f4e9921d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:14f267f8b5d64463820ba3e3b1e6555728e1f3f080739e38d82bfc0766b066f0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:64d9a97277aec80e1fac6520dcd7329bd91771d55fc0d0f6793accac2f32f25f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:cd8bd44a9797fec18afe84c65ca1f95a498e5b062a6b7dfa70eaef37b1958fb1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:f05db0de5937947ee8321bfba53407ce5c1e4d43ab41fc5556d2961a531046a0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:b6461e2cdfe3f105d6d222fe891faddee27bcbc1297311fb4d65b30013c81e24
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:e6db54ed358aa75a6185a7584ef4d7b34c333c58bd5506e9fdc5ca41df0c909a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:96f5248c1d6e5cf3e90e6581130a708ec684a5e2a41e2e749dee1d36a86c9d51
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:eca1bfd8732d8808c0f1d25a75d927fe8f78c257b75b021b39c50fa856197a57
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:81ca0c88cb137cd083d82865bf7bee17538f3833fc041b1bcbddf764e0aa3a67
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:1010c06c6d03db4ccf0a8bdb23ae7dd0ce488a18f099631df3196fd271470731
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:85308f2db7cfb9026b85b2904122dcddad95a79570815fa67587833b2e4fe3d6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:0d8e0de327baa0856fd85eb28c11063f48b2e11bb53549d3c69d99abd6e8ca0f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:1e7cab2dacb541d4af2c59c8530e59dc72c00ff6bac0ece34bf155b60875056a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:c7762c7db0f04adcf6f2237a915c9e3877346615f6f700e2aca3c2ae3e5e47cf