Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.36.x (compat)

CIS
linux/amd64
debian 13
Tags:

1.36-compat, 1.36-debian-compat, 1.36-debian13-compat, 1.36.4-compat, 1.36.4-debian-compat, 1.36.4-debian13-compat

Index digest:

sha256:ed07eb6f50d6915dbbd648bea97d02b69cd81f777f0130c51d3c13f218b66360

Manifest digest:

sha256:299d2c477b83c0cdc2da369b68db0233dc8637f72f7d174e5b3d28cf522331dd

Size

41.42 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.36-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.36-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:d61a2b547c9b40835a35a86084c0395cb81532b134555b1cbd04a721156458a3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:55bf2bc999378da6021be11b74b34454df51417028d1ff888b8a0daf4e430afd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:226800dba99d6ab519263fa89453a0167251d9ac6f5cf6c32e96ba9c47c14770
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:e5cb500065a5b92dd2d026ea7a205b419e15883f889ac8ca00c3b12a6cc7115f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:7d5b33812598d74a41f24bc8ddaeb6c02112ec1d2a63b18595b35fa044ec624a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:47006fd8dbef0abca5a53752902df92575d5e43898fe2c4106a9b6ae99b1402e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:1bbb3e17cd9668a4df242db6e75705ddbe97f0ab7239dc7e4d6cff3ba9bfe0b2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:89227dbf13153fa23d54c3579e55c66e967fe801d56fb6a4c3733365c8cbbfa1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:c4d29f259c5a2fe1aa643accd394d619c72e5ab8fadac9915745d2c56adee393
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:140ed7256a5e892be67b60b6a9311f469996975d8291e0db70a771c06bb265b3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:0e8a6a0bce650552583c06d354944286ec16a805649de5a353402cfce38a77a9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:f29f1bc84a3a0bd2b09ed8c625ddad13f21e09dac64d4de19000aa9b57d584ba
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:471d9008ec54af55419787f2ac4a5c836f43434b88a887d8029a8c702476f7d3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:964c951e84c643b2c22a06ceee019f4d840872549f662c08985c103aca46c61b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:43d26d2255320223f619a6b1c395500a971c87888f0b5b967a116ccaaac5ab7c