Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.35-debian-dev, 1.35-debian13-dev, 1.35-dev, 1.35.9-debian-dev, 1.35.9-debian13-dev, 1.35.9-dev

Index digest:

sha256:0a7428e053b300515e0866a2079a37ba08380e8cc08a5d40253718cf78b0bf7f

Manifest digest:

sha256:428f1c9f1e6839713d3c4addd8cf8a797447c4a5daea2ccb20b96824440e4e3c

Size

81.89 MB

Last pushed

10 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.35-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.35-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:d135d114e00ff0781d63e87d59ba0c9826bf9f5881445b7085353190d828cec9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:7ae0062c21d2c9829ed6a8dc84359a1d23e84a932395851403b2b18e9ea85fff
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:c2c6ed9b1cbdc11f2c139e1fbff0a0db269f64bba5da417dc814ecf12c1732f0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:89ab3fec87b1da7294cae3bb009406d0bdb2d86571e96602d1ebab2aa73ed02e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:0ba16d9126abe5f2969c25dd4318928c0cdbda5d116f30da302eb096a26c5e8a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:7b782ffc3db6893a049fb80c2f9403f3004b34787b96334acd0413b19e792ef6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:46b2e39a8af02d0504f7ea9803a436ef489aae2513c304756c0da8f80163092f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:3e929a12fbb6a0f3311a8fcdc27275d1a592bfa029bf4617518e9e84aedc7fe0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:6ca7e99d54b783e7190b6e1915c7fccf0d3317543974dc5df69885833c038fa9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:980bc6adb3e66c0fb269684d6b50b7661d5ad95d838756c37832e12992888149
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:3c8b538c713dd83a28823051719ee93608b5b53bdcf13b590338db9bc3fcc171
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:fd9d0fff0189079fb8bbd243d94b533b44f468feaaf1b73dc13d7f872f0951f2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:463bd6e4c8ee4651f036d398904d455c01666510fb3cf3308d9223177858339d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:dccf42600e921940fce2bc61360135e602ec856cc5ec7c1900fa848bd5bd5438
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:2688889d75acc4337717a240fea29541d2f0fb2afe94beba317158b44d4f1201