Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine-fips-dev, 1-alpine3.23-fips-dev, 1.35-alpine-fips-dev, 1.35-alpine3.23-fips-dev, 1.35.9-alpine-fips-dev, 1.35.9-alpine3.23-fips-dev

Index digest:

sha256:a66f2d1017c2d16746a86920c2060dee4026a44e2a905771a6e163bb3c67aa30

Manifest digest:

sha256:5228b0251df566681d167122bb0de15da2cd0f7bb54a3c006e7cb65407232af1

Size

64.69 MB

Last pushed

24 hours ago

Vulnerabilities

1
4
1
0
1

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:d4c74642bf227b550d1de1de845692cfb7f150cea27823355ba4925b2a66dbb2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:ec8e6e01be3079ab9819ab12e5ccfefde5b8d1f0ec51918076055de1a0170b78
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:66da86dac803c8d7500e2b5e1352703b7af8aca70cae4d75cd3f8c7cf67b159c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:82c8f2b7462936b2f5a59ef39acbc7d3d5c27d401c4cab2fc7ece19bd76a67cd
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:f3b51640685f497cd5cdd226504023bc31a6569c487fd2702cf0854af85dc235
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:5ed2f7f8034f0122e14c8331cdef23f6bcbe97c397d1912d008a7cb25eef072d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:29e4f60afb3e4eeedd1bbd8a7cca4cde813aa5aec0509a839993619906fb8d5f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:d015ecb7da93a8e6a46243a08fa471c5cc1e958ec54ad11c45d3147dbc3c0981
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:e46156510fd2ca42e6cc3b8888e1db132eed337e9379d4966ea93bd158e994f7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:891683e2a9552b74d1bcf6fe7b0595b37a48501428722636dd36d12162533595
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:06a45b266cca6112b17eb171c54fa4913c0001491845155d52d2fc54367d4337
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:dd1ed5039bcadfac07ae26af5f319fd9e1982ef9ba37f41ba810a8a4841d3324
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:bcf2e785164acd5249855cd3600ae8eb9962dad065a68dbc6489aa50bd829f92
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:1bb06c38e4bc8d56636c65c5a0f899d8c19be3680bc89bc44f79036452070eca
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:171c1392e14c97b9599f1930673cbecfe6277a8f5fceec0584f9e221f7631d15
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:6cddcd6db8d16cc8c742136cccae27e8a3e05fc551f6cc78eec10c66d221850b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:e2d49158d76e4df649dd99cb8f32e1d6280de18a1f9db5078c8c1c526aa3dc77