Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine-dev, 1-alpine3.23-dev, 1.35-alpine-dev, 1.35-alpine3.23-dev, 1.35.9-alpine-dev, 1.35.9-alpine3.23-dev

Index digest:

sha256:e9c9f9eacf3e031324b00877f36af8de6fdc946888fa47fc64d17b2d1a9b83de

Manifest digest:

sha256:defb876a5068590ca74d004660567281e6f98736fd39a65d9a9afb252093abb5

Size

63.68 MB

Last pushed

1 day ago

Vulnerabilities

0
0
1
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:6f638c30c51dcd128cc8f26554f0d909bac428efa454572d0c6051b97f7a0f6f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:67b4feb3c7752bbabe790b1fa66213cda53554b266363b6227e36274c6161a65
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:4ac110514425ee7b95267d612e6c184a27f2130cf6b38c98846322fb522dbba7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:77d03ae32066f97d7b91912783de507a797648b52605c2c02da9cca61a2fb8d1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:6cab3e2faf890ba1b7f31a93c6e5d3c7d051b6a7787958f5241c4c44f5eabfd7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:0358f038ed8b77a4d8f0d192b9e6a1f857bcdcfd8ee9227a460546fe361b675d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:9e21c17dedf5dd9131a32a45bb708e9cda6d3936c891f9a8a779b4c7e2cd3275
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:c77d3b3510bfa392c0885b78169f19a0e3420dc9f2a634c484884ffcb917effe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:a16e58c7436aab85a5227f1b9ab7be04f2a418a92859f4e83ca254c0b466b963
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:32ba915a3f88ec363680d1f65438ac5397bc48f7680f59505554b475e066cbd9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:8b935ad9e97027acba04504a46da5a62bc6b18eef7d22ee0dd162355dbaaa0bd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:15cb6603bf79ed8538185ad08d4fb73aa455d27a7d93d025d471df8ee93cd9c9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:7282e81d02910c24f8242ca7448d924e37f33e8931da5c271253a06000fa3807
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:52f846d9f91dc1f7f8d2639d15aa68f16b3705b83c88f5d0101587a6e832cc33
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:824cdab77483cca6a1a51d51d8f76e3d755b2183e36887d316e30274db1b9cee