Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.35-debian-dev, 1.35-debian13-dev, 1.35-dev, 1.35.8-debian-dev, 1.35.8-debian13-dev, 1.35.8-dev

Index digest:

sha256:ffbe8cf650e5b9b3e43cc14d43823ef1c5607bd991b23f03242b482b05a49fd1

Manifest digest:

sha256:18709a96673860242bf3b4467af452ed2cc280c6b4d0038ef4c0464557a8e8ec

Size

81.84 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.35-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.35-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:9c53bfb9d04958bf69bb47727bba6e26bc3201bec7f323f9188c7b8074d2a0af
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:669ab049867bc9ec48b406f32bd6f3de35571dd80b6108d9e89bf261ad5ab5f7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:af3bd2dc9aaa115f135cb775de30c730a621aeb46e1f2ef67a7277ea6c98f078
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:1aa487458d570fd97bcb86e7776674c87a8a49cbdced09d95938fb1313f0eebe
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:33f50942dbdc9a8ad9da6e90f00b9c7931b41a0d4e3e4a7523b11d4366331b99
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:c33e55f45ed19fa7914d753c6038d5ef2cd8a8dc76d5e8ab21e7ff293164ec8e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:0cc82d489ecd66ab56574caf91d0a8aa77878b548d3768ad32e1acefc2307adb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:301effc3fc5f576208ac84602ca6fdfa7afc62606b7387c9874fb315a5d21068
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:fb032fadefbb60252c0a12f1f26590d82bf5ac0102db93fa71c841c2634bcda9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:a4a3cebb2efc139a325c7cb1233c54dc708e83b2e77b8824f4c64e77a81bc75c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:67e23bb836f57801d98952f2903c512abd6f96d62112dcfe94e0129c5e5d358b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:6d31e7b77e37e1843ca62e0362ba43b5889fa16110095532761b436d0b2f108b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:9a914a5219decfd58ee61865011ebc53eddef6b9705a2407eb7f13cc669468bb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:5afa142b9eaee0b481ff7349b7bc5b20dfb8ad304de4a055d771107beb046ff6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:6ced0581a48ac3a916039068a13848175ab6c354acf220126369d967b4c1d2b4