Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (compat)

CIS
linux/amd64
debian 13
Tags:

1.35-compat, 1.35-debian-compat, 1.35-debian13-compat, 1.35.9-compat, 1.35.9-debian-compat, 1.35.9-debian13-compat

Index digest:

sha256:462ba8989d5294b290049f6a9bb4a7460a2f5185da5faa9bfce9f5d36bdd5f59

Manifest digest:

sha256:e6f73fdd561537f0aae348115cda63dae9e5a72533528bbdd71ee5810c311baa

Size

41.10 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.35-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.35-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:a6d0e04a9a7b61aa21c04a5a9182b10227d512657673044b4ea5d54d6391432c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:96473046108b9daefce14632a9b58ea3f76a44931ff21a66649b0e692fc67a88
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:1efb79315cbad76fc0dadaa8462f31a6590dc1a4b678abc7f296f945e608ed13
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:54447ecc9ec5112a2a2558e2ab953b1bf48776f94b7e71b42a52a2825e8b805e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:4f7b0985ea5fa4447a681c824475c7cf887aa659d55b438e6045df9d1d1c4813
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:1efe2083e0987410d9eb2bb6738c8858e8377f6546d5d2566c7261a4d91b0419
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:fcf680e29f4ebf69103403f6801bfc3e0a41afa0645b18c17ea2044e6aff1e46
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:28894340f752396722e84b3fb6a3005c159afd9dd23bbf0a88409a309a164d67
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:7245eb5ce6ed1238a75e96f381880a065cdc232997cd4ca5c85e50b042671093
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:8a2f0f022de155aea020b95f46f10ded2a5855095c94ae25df8f16bd5298bbd9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:9e7cd499700efd33418bb6f761a393162111c6097089d2efebbcec41f36399a4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:0a96167a372f77ee8e6f51d03d8eab6b3a95dd7a9d5035d6d8ceff44ad9d2f09
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:31deac090f6617b72e8b87bffcbba6a2806b7a55c3ef850abcf32d6d6166b335
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:f938a9943ac457b1d34927d62a141910ee300690f3589b8b9748f4961173c0b9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:d21cf326e2ed6159d465eddc56387652e7b336588d5f66b877bc7b6ec700d4bf