Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine-fips-dev, 1-alpine3.23-fips-dev, 1.35-alpine-fips-dev, 1.35-alpine3.23-fips-dev, 1.35.9-alpine-fips-dev, 1.35.9-alpine3.23-fips-dev

Index digest:

sha256:71121f0a2daaf60a54ac7994694dd9395d3d31d16efc63fba6b2b3c47c7c0db6

Manifest digest:

sha256:31969a1b8f612693878df37f565cf689a5ba08b54c4fb1204db6db9f397faa44

Size

64.68 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
1
0
1

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:9e806231f407ceee4ee131e49e9ff7a1335686c87b5cd7e39ffb32936cf11243
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:113a5c5dd1605a873e5ccc82abc13e36ae404dd6216d565f3620be2086e637e0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:df7e9ae59c87435f53689b1320ebb2459d22390f5ec5169af02ad0f3a4c8345d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:e323663feb3f10b41b85f50593c6bc00a70b148d13b51ffe94876738ee50dd94
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:bb2dd0a4689554c6d755df5f34ac30a0f474dad9ac01e7597aeed149a418895b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:320458d4b6a816573ee5e3273f8392173b2a0a7f50f79bf6663e2eb279703bb9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:ef003ac5cc7ea7bea1690085c54b57fafe76d0733b3a764becbd06a75c7a8e22
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:05fc89906b0a01914d76df949a7ef1d896c6dd081ff86427894aaddc69e75bef
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:b4829fcfa5972f2774708da06d2a817de747401b61c96f19afdb6b66b8856848
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:3052ece2d76dbc8eef8b5658b5a912de5011450da5ee09d99c4451d48b421d8a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:c04ff73a73368d25acc4075728d1a51f6c25804762fae0635f4d54008feb8264
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:23b1413e5fd36da4b5da9b4308f6013f47c7561991c47dd4408926c1552b2b0d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:aef7d9b3421c5b399de6723d87159d520bb994aa84e253bbbdd3e3ec33816783
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:e5ab5f0a280611cecfe3fc77c7b4b9b0f6ff731b5f9c49a840e14484854cb91c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:d56f7656fd5d4fe05c3c7a91a75a3c860e17bacc102471e55cfeae44c178fc60
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:b61c5340460384236c46a4e7a6bd1899e03ba14a832a73d4c3b89e1863420b71
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:7bedeb11efcc3221d567cd83a87dd7a9582ba40c30cbf15a01bcc2e651f70c29