Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine-dev, 1-alpine3.23-dev, 1.35-alpine-dev, 1.35-alpine3.23-dev, 1.35.9-alpine-dev, 1.35.9-alpine3.23-dev

Index digest:

sha256:19558f6b1b2474fb99b69113d2638ee2848e5692ccffa394f39808d35bbddbab

Manifest digest:

sha256:d9dc9bbc0f1e58d28ea86551e4edbf6d4288c7ecc7fa99b4e0186d0806ecd1bc

Size

63.68 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
1
0
1

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:92efa2c51dab66e29a15da2f2b0da8f242a589abbc188db68dd7dd8d637bc8fe
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:142c2f16fab7671c877afc92c74643e6ade7501e8278c2987df9997766407620
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:45763e8ff209969ffaa4af08f4812ad31c4ee34c5bafb83ce3a16f4a045e6ead
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:95e5d1794433295994875f230cc93bd5017f3cf371b20873db4dbb48c324da1c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:fd05bae6544c091631ce368d961b5f0a70f71a4d1c6d676ef8b13bfee0ceef59
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:ea55dd3d608c278393cd393a983548e807707c99ca6098a7bcfdb036d4167382
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:c441652e6d40001b94602f9f3818c0ae9761f979014ea918e6ed6f4c9dfb0e4c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:c0f0c1e739d6bea8f9a898aa720eef0108d96ea33ae9afa82e1af3fd47a9aa37
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:2a692b07a47dcb5e3da09ae730ff264d2c61d821b26bb8ecbcddb0f0e5e4f3c0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:8d96234dd9dab4c92299b4fc58bef3456876e34f2da5df868d5be5d733f1afd3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:c93c5311d795e8e32d516f14f4517f8435996c17e47ef2247a33dfe80d475108
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:c4c28a0a93f50b9cb52f3303745d52c271a5b15d29e99cafdfec9d3170c34087
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:85831ae138b2f828be8d7ba52b656bfcc6195f4b63629ab0df096d0571b6baef
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:d9a2c1501e988d7cbd38b37f9e7197e7d213be01833938046de8ae95591d2011
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:fecc24157a1284b5dbd01260d1900592425c0056bc8640a61bf61b52eb7327f3