Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine-dev, 1-alpine3.23-dev, 1.35-alpine-dev, 1.35-alpine3.23-dev, 1.35.9-alpine-dev, 1.35.9-alpine3.23-dev

Index digest:

sha256:eb6d317f5eb7f6c066ef1a210fa91d803d151a12e4a925b651b5d4e8b0219568

Manifest digest:

sha256:7ce93a317b2dca76239b00592b28a8607ee2c636263e340ac4963d87df3f90b3

Size

63.68 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:2cda715296626bf840dd5fdc2c5f2b9834e5ca8e1612026fa01c4e6991645b26
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:65db3c8f65aa5e37ed4d6b1a9ee30d3ad1e799673bf486200e69accbba6b9ca0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:5a9c7179b2d20ab466b5b210b95c9c9f923da022a4cb7040abd79e0eaa0cec0b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:ed70b229c85b109448c6503b06f79f66bbab4d95a0cfe10a99e7206b71e94b06
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:f9c8c1e944e4d2d7e9963bfa756116d18d4bfc236ee5723f3768d18bee1565c9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:4333257d50e64b78e8ff3fec9da80aebec5875a52380de6df7cdcaf902502b0e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:c735df8c95446d917755a701c7514e3e9201f3ae3db26d6faf90f0a2cc083365
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:95f1bed0d782b5af284b4eeab0951028b0da478c7ca394e21dee6492de40d98d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:db2fe1f4b0a3c3876f5fb07541a9bb8cf5daef8d2ea408a76a93514fb5662c09
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:4970ca1f0504b3713031bb60b57655b337dc25d7be9afd689acc65d929d08dae
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:eb6da0bd9e54d4c1441ab9e47d0adcfaf878730463c47b6710e7b998892703a1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:054b8d73b753fc851378978d3e9e9ea151fa3146acd61b91d898aa4516627a66
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:d16c9e94a3b9d29910dc05814106e4454465663024675285c8b8c510385a80a4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:e6a775bc4c7cf07cdc538777aef2ed0bbfad6d0cb6caf20dfc1e25edfc428c21
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:626380663d9511e6bb31e79477375df82ef3ead4b95d6ed243690c34bfd770bc