Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine-dev, 1-alpine3.23-dev, 1.35-alpine-dev, 1.35-alpine3.23-dev, 1.35.9-alpine-dev, 1.35.9-alpine3.23-dev

Index digest:

sha256:705ae7a523778dfd3c499726c0629df40c1dde5b8ac596580bbd2dfaf9a7676b

Manifest digest:

sha256:f6b9416b91e17fc54e4e00a8353b2d5a214a5b48c6e9015f1d9cb34d3dd27efa

Size

63.67 MB

Last pushed

4 days ago

Vulnerabilities

0
0
1
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:9d51527834907207c4cb8c08cd83d86401b21ea3c247e74fe906eab593562745
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:94b51b70d49088ace5cd71ddd6d4f2ab42da716c0503d7b17b8f240c9d9925d5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:62ee99af883c3c4819e2cb442cf8a0487990fd2bdb9eb700691e60131713d2c0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:8d697a1585030471d8f4fd33e1327d48bc3939d1aed83d5b86c79b23561cd0f2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:9952285ae0c4818aeb36c020de5f84d78c844df16a2b6e3d69e096807130f663
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:6bc8c835291167f6254ce9c8470e073212a864b3e604ed656f303712a5cf100d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:1de50c2df9ef07c3225224c628eec3cd4da940324e02fe177246e26553b744de
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:24836f349e937449d57d6def25bb9242ee66b88901beb9f6bd5f4a57df5b917a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:3a30dd30156b2470018d4869cae283c1c952b8d671e053722c809dbcdf96317a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:ef4cbacd2b0ccf3980eec51bdaca70b855b326b0a14be6c58e7352f840ff3ef4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:0ea87f83ab79160087cce42fd89cef73600f607e864565a472205e2a0344f9b6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:fa04cbec4f543087df7028a3d5edebe3b7d47d4d1de97b3b7ad85aa438979de3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:86b66a2f910418f2c097599e3b1a9f46ef87c6ae0484e63aa4864ca4803f3582
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:e8457a734dd7b726bc5db5de888f3abe652880d126c24fefdd2da4be9dd8f96f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:4aa1b22518b738b2b14fdd6632610324e0bd5217b481a8944633bdf4047afeef