Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine, 1-alpine3.23, 1.35-alpine, 1.35-alpine3.23, 1.35.9-alpine, 1.35.9-alpine3.23

Index digest:

sha256:4f84558ee06d20213eda180ea880958c92da6f8ff0d4db21b49fe52a2d62aa34

Manifest digest:

sha256:5a5ccd3a3fffec38dae51dbbdd11a67cdd03bf4b3958163eac0bce11079d45f6

Size

29.26 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:9aba9f7eeb35916bed5a18b69749c6fc2466ee0f6333332b82095c664e5961f3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:25cf04441cb3170b2601747556a0425da0d1bbde803dbf496ae755131b81af45
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:e6129bd40c9cb8d200d7cf42f368c29f2be077d10f24cb28a337ff55c3b2e72f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:883f58acca9a9c10ae1655f2f46fbbcf29e5b1302c3761da46765215d95fef69
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:856f361ffec8f83f7f81fc88ac7367591cd623e57c07a65c3b2b69b86e24b69e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:48d6974b6cb35efdd33e9daf0ff0b99e3dfdb69cd100ca7fe6184f139389a607
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:fa19b80ee0117ebda54b0497409a9b4a9dc00149b1203497ca11bf9a58cd4e4c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:4f2192360605ee8bd1a6de1958926e137eb5e62bdbfc75aa9646441ec8e6387f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:aa7976dd8f59d4d234c28c5655bfdfb82cfad5dc7b90b60d2b34dc04e115811d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:25a1cd3561c3e99b5b9ed5641668570fdfa14bba98026fad8e9e5df925b0c75f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:21dac21d1cec049dd3d7fe980db744659fff340ac6ed216cc6734b538b059f4f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:21a70eb2fe4ccabf46b173d67ffe44f101da9cff89d3358c6faab8822ecd76b4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:16ea8767907cb628b7996c4e61025610c44b6c6cb6cfce1a02255316c79f8d83
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:cac0aeae73f468ae1f851168e006ba7cc488a20bb9c1607fdc6b3a147d1764a4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:37b50bee79ae87b8d33595c1fb03e99828195eac22d7aba6fe3e7514bd49694e