Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.34.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1.34-alpine-fips-dev, 1.34-alpine3.23-fips-dev, 1.34.12-alpine-fips-dev, 1.34.12-alpine3.23-fips-dev

Index digest:

sha256:49002894f663d8c6ae515169ee9a55e2f6084a7c65e28da02f3743d22a10483f

Manifest digest:

sha256:1d41f1d0fe77dc7cccc7b6a3efd37130d4943ed05c832b9f30070055a41172ad

Size

66.03 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
1
0
0

Support

Ends Oct 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.34-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.34-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:813073a8bc0e072cf8c34d6ea8e4494c1e2d1b7bfc206ec49c27b3de3d7fd1a9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:d74ffb522ed00bc02f3b46c5c96f94b0dad7e956f40d362f9ee92b3b4f01cc80
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:c4ddf4fe7c68a140e1132a8596d1a7897a71f69108d9a455828444525417eed2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:9f9208670dfd7c73432c72a5420b4a3b7ab0b431145283bd2f79346dbc3122e6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:5bc79b8d43de7c4701cd6cbd9cdeb99e363c1945975c7a1a3adfc5cfec7f7f68
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:dae34ac93e460647eac7c9137f4540ccfdc548a269d3aa9e29e4fb0aa115c039
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:c8c89983c0771070e919aa3aae440e9f524a8ef2d572472ce222ebbec120323c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:03601edc0796f89a7d872b06a4f1455a53c9eb508664b4abdc5390f6be85fa31
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:09967c72ad95f5af239d1bdd8a2dee85ee036207aa3e41c2e001ee98c8a1465c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:2cef59925589eaf05b672cfccd006930259016e04c54479d622acbb0b05115f4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:f4ed082dd1814135a0912008c87d6d26847d3aa0c8f916eb727e7995966fa9b8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:ea0ec4210cbb510ea477edc40ab56a40a2626ae0aa491af53ffa11ee37091c73
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:f96fa07df6c2c5289ff82fc49930f135c055de6be45eaf4aebd11b80c8e871f8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:ac270d16c7a1320f0976832b1089d0495ab5d91db2f609fbe90d507b1e11534e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:08485db920283479ce8ecd4bdcc94b6e5590a3041346f88fb2cfb9d05a3b0594
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:e8d5a8b749caf49a3197e29ed1cce1dd8bd3cc97a6baa85e5ad0344a8cc6c876
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:5bc6862c23c4908ee67b2cd71e5985dad96eb1935bb443438290e2916646ceb4