Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine-fips-dev, 1-alpine3.23-fips-dev, 1.35-alpine-fips-dev, 1.35-alpine3.23-fips-dev, 1.35.9-alpine-fips-dev, 1.35.9-alpine3.23-fips-dev

Index digest:

sha256:7a5f1c0e1320b9da38e40d9424b068d7c3306e32394da7fd4503acfc4490516b

Manifest digest:

sha256:e022e545543ff394ccd4eacbf1f4887d0a5e92439b1d465dcf6f0202d0b7dec9

Size

64.69 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:9c8b14a6512bf5fc2f89761c14c17d6648764987b4a6698648734ae3e41ca477
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:43336c55c56ee9fe455b02227993b474c43fa6c389a052214d69df6f1c3609c2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:f9938f6ebbfced58996340774ff5baf95a9e3457dcaaf45849cbc30c9d9c1698
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:5df19206ec2324dc4cdc77ddc2fafdb8712a92f73ca77f5e411d163074c8cd3b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:c667a38ce1ec87b4816d8f3cf9427836a2c3cd158f9f3e67dd310487358511f8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:067ce42f4ecf32f5b50412e311f53d5d2c2cc8c7fc408769683c6f1b2fdc61f5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:7fa4e93e4bf756341726499907c41b08f1e0101f64b60abd39235f7c266fa640
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:3a1fb1d73ce8527fa982862ffb80c68a00a51d3ee41694ad55186293f1ba31b5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:1713d2755b66485944394d1d0b80ece89620d7f1a1b45bc86785eeaf91ef7d32
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:af5c8aecbd1494560de20177a01edc56464a727c46f788b6b862cd68fec3fc9f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:051c1811b45ded59f8d3eb5327f2ac10d3e7610507fa449ff1fb3c4ede58d705
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:1791dcbce0e08e9e991b1eaf3cc01d0d2fcdd85481dc9293a7e0e9bb0f04015f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:3defc2dcd6f1feb2eae31a3723cfabfc753f59b7f50b73a8ef384ecc961738af
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:503121909047b39669e5b3a84086fd1ef43d14568bce430b960e792b4baf6d90
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:c9491d6c8e2725a23f6bc1d78b3c7fe46507c125a87f9117d08f285a2557b4c2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:948f2461b217aa9e281b6617f5636d6b5267a7c712bb59a3c795801f0ab77648
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:92cbe23a82a26ac42140655683b6d55077539e1b6ddc1e9965c75b63380d9330