Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.35-debian-dev, 1.35-debian13-dev, 1.35-dev, 1.35.9-debian-dev, 1.35.9-debian13-dev, 1.35.9-dev

Index digest:

sha256:21a6c883d29e9dd74b996004cd92b28ad5b5bae03f2317d0694b7546c5c1e895

Manifest digest:

sha256:1a9ef853e07899561cd741899cd99151dd5ab44ae8cf97982df476a2ec85fed0

Size

81.89 MB

Last pushed

18 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.35-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.35-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:561de229ad850bed0a6578d7a2f4980015a662db122d7185257c3d31377c207f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:06f42762a192595647d8aed267cc464c80e8019fe9d65928a3c9b654f43b766d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:79eb5994bb8bb8076c6eca762b342a4f5f8494aab9e6fe2fed8e6531a9fd1ead
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:821c595304c9acd2f671b30ba2a1dd5f514864d7f5180d243826c1686faf5346
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:1a1d6540a91e04a81de966a80d75f349ff0c7dc02ace712f65cd31bdd5be055b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:619e128c6ff2aba62c0df84f179595074fca379d3e91d51cb9719f96f093048f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:1368cfc2ebf5ec9652ff88f105fd47c018c7b891df514d967ebab7e315f08624
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:f3775f6bb9dae1a698f7b342438c02bf371420aec78ab2cbd00cb3b0482c2b6f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:f70a3e9561f944f981c639cba9d52357d99370b4fd580b6560ba563b09ae4692
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:eac4cf264c71bb9c2b9dd9a77c1785a8c448988847510c579a8edab84f51619e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:536363d62e72e5ee13881ce5a4ed6acd22f171af4064bef0a9ac8bcb0ba2ba95
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:110d79d4072f521c7edaf48b50924605131038d0510d5007dc0e05ff3951819a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:bd66dd51d879ed3a0b095902b4c8e88949a0b581cb48ad6266ff6da4f60b2189
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:2f477d5ce5006947cc560cebe263487df60841e06e6b00d564689ef8e732904a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:5b787e80fa548276c1b1242efb764d7614e9923a680770405c70ab0e8e1708a5