Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine-dev, 1-alpine3.23-dev, 1.35-alpine-dev, 1.35-alpine3.23-dev, 1.35.9-alpine-dev, 1.35.9-alpine3.23-dev

Index digest:

sha256:dd5b285a704172958af20b80eb69d1dc766686a3f768f864e4861672966859c9

Manifest digest:

sha256:654223a2e35314bcc67c2d2fd8b1e9bf5e7ab39026019e07737fac46f88b062c

Size

63.68 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
1
0
1

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:0bb0ea73498dbd3f8fb1b9211e04a0dc7a90b7d0261d7884f67cb4db26c2c7dd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:f11b56f7c45870220838e78be92f3b4917db87da6be428dff7e44d498d3ceeca
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:5d28c69661b1c4fe85b58fce2fca8beed2991009771c7bcbc735d3a7ceeeb2ca
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:9d2e6df2a3378573a8f879caf3e4c23750e2ea4fd03d1475d4aae5a3217cad1f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:91f6560a3a2271be8b423ff15ea09bf03e11dc063423624312a7ed328301bbe8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:389488dbd22e2b0669524b82b28b43ced0e1a46fd0596e0ee1b2825706a99d34
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:ba87bcb12ea71700d61afbf2964ffc8c2219ac13a6d4fdf50fa9b91beca777f5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:946dd8cf60dad7824628a460cdfd739581379a9a782d4ba36123a7be87d055c8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:e95805b26cfac202679d77851956ae31eafda6cbcef447be460cd21c26725411
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:646e441173f05527b1eb0419617fc24ebdaab3d1b632417d80eda781c0d6e85c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:4ec4699f6d4d93295cea7e55adae5c759d18656f29ac418264d4f6aac567d1ec
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:ede8cd6ed3dda8a0e11bc0c93be1110f7dd1072035b505c624b849286494f09b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:7a89aec0da8cc1e092d8dcb97408675726ae63e621e480f59cc1f58f58bf0220
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:e8e34e8490c748da5ec0c7c9cec5fd7c118630a09b4f528005bd3badf193346a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:6e53796233dc64e26995a9c3f4acb4d7ad979b8e24d17fd44ff741bb15e31836