Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.35-debian-dev, 1.35-debian13-dev, 1.35-dev, 1.35.8-debian-dev, 1.35.8-debian13-dev, 1.35.8-dev

Index digest:

sha256:6fc19b82c929ce15ba0479d9f79586ff00ecf0d8928c09199f573623f820c6be

Manifest digest:

sha256:973ca8e290f92f62f149b57932754248efc0623c56536fdef1cd4bc939d3c2be

Size

81.88 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.35-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.35-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:61343d82bbc7e68afad99539b8639d329763fe68b285fa64b84cab1964a4c453
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:6950204f8b55a788339144314f91f5735c19455c05ce28d6f616d1f6c76e7add
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:c0a077ae967895ec05f1a8d418b3011f60702c5c1ebc42635f4ba697431e9d46
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:f144e472b71375c5d43a6c78a3b8619203f1880da1ce63bcbcf7553636d1b096
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:6b78ea2d3633148acfd747064a07b6275561030c89eb5739a6cd014539f0d71b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:034e404997c7e3d5972ad91cc65e5a9e759a3150d658a183ac233f5b5fe0dd45
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:9ff4d4118f536d1dfe4cfc49113f86ee5d147a5b6eb6fddc1dee83acfa6ebb9a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:77efa0e22c7ae78abbdcb389c3dc8dd92530a6dae2007ff5402c5b2fc5632462
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:edecfba796a0cb0fd328cbd66236f4aee9b08d048b3f06a86eb08deb60afa7f7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:7187b7ae73104524ac10f444ee642b27d23573e01c88e3d536dea90a028a7b05
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:bf92d098203d122f2fa19a0d32439b4a7bf17943ca69a8780cd8582f5078d6bc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:43d754f7f4d3584c45d403c4c52971e29cb78c6286cbc10b017ff477ea518f5b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:844777e02389d6b502e2037ffd2759b1a1b49ed7114fabb45985040f576b1afd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:e862c7d4d260b4b7c0a08db21d02e357f829e0ea08ab86b43ee77286e7bc368a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:bb9ca1b2165c4b2480eb6bdb2e410968f947968a0cdf9f0e780062fb0c4313ec