Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.36.x (compat)

CIS
linux/amd64
debian 13
Tags:

1.36-compat, 1.36-debian-compat, 1.36-debian13-compat, 1.36.4-compat, 1.36.4-debian-compat, 1.36.4-debian13-compat

Index digest:

sha256:8b2ca5603a1b77e87aecd13a86ee309c8db8e14412e1943d68d39249ce9b1c1c

Manifest digest:

sha256:634e8e0649a6b626c59da730c98ad55d1effbf522e14c99c8bb6c3f6b558d216

Size

41.41 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.36-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.36-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:db9ec876bdf0a6a24696c6f958b7f505d1d3e590fda65413143074648cc05477
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:70671cb8b543643e1876623abff994cfe711da3843f79c17d8bccfcbc9932f3c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:02d24f576e7dd0127275145e6c88daeca15b405a576c6ef19dbd9c9d238f5f1c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:3539fc13c0f910e7c6765e58bbeb1fad08f8be97da21f6cd6e116dbe9b9d2839
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:837775b54ed82ae8d38969d2c5012907e1097613709b4540e4c72ac81c5db2c4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:99b40eb34963b1b35083dcba4e80f1314c9ad3f14c9792512dda60d629a56fc5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:28d64dff01c12f18b44e14b5ae58a6dc0b430675f2bfdfa44a38062bda492070
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:9583b62d1c8dc51d84c2950434d68c3e0bb835b8acac3c3f2829fe3ca4fc8fa5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:a9755a349e17c872aa7ea511d5e74a88a3edfebfc3e28ecb71eb14763c9baca2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:46e03afc03c1a7914de5730a22d460a77521c92400efb79319bd356278ec335a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:ce0445d8a5f6fdecb0661a963087c4003000d8e83a9da96be85b244cd707d266
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:7fdb94fda2bc3241ba1ead99ab1e1b3ea29d4d52a98aa20862f551421561dd25
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:313ea0942170fb301e0657b999ee6ae5589427ba9701829f170c0bb0907339f4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:b3cf85c0e76ed87e046163dcc481c465e90a6feac9f00ef48cd8625b8f411396
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:0ac9b40c98585d4df4d255fbf717f74035b6a4e444712b71a1b40617b610a5ed