Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.35-debian-dev, 1.35-debian13-dev, 1.35-dev, 1.35.9-debian-dev, 1.35.9-debian13-dev, 1.35.9-dev

Index digest:

sha256:c690f1bc7e93d8e9f5d0d7fef1bd9e62701536106198e999c63301e79c7167cc

Manifest digest:

sha256:a0e6676012208b57e7238018b1b5ca0f11189e0f0b16772f505d275628e650e3

Size

81.89 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.35-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.35-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:40957603386ec189deb5a7d64b58eb27ce884bd8cc7f6214ba70a2a02ab4cff4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:41a9936ef54e2ac89c7b96a25fef8c48c5c069921990be4d9b0da960af30f969
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:853ea1fba68153a6ab550aea03db51f87ed7728df33bcc2eb7df9d0992695e20
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:96dcddc070e227017c4fb92dbe56fb85c072e35c3536c8750b22e8f09b724982
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:17066237ad76deef1a8e0128b874dac002127f79620ab52d71ca018caf5f1da8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:47ec3c10c096c52d9574ea6e199449fe4f3efb3416c6ebab40831549e84838d7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:bdb5702b9b4b0cc09c5fdb9f6244089b7232b48443abb585ec8489dd7b6c095f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:557a99b0d85e81ff535c16dcae20f618b83b8c65a99c712bc5db34167859697f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:19540992f437c91ca3b94b49d891448f9d89aa732dfdd3c6da1f16397a7966b0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:30fb173c60f24ad2d4f6e135f9da9007fbcaa3ce039d1586f7e54075d2598899
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:de5f8bf016f4d33baaa0053d01b79418cb2a2006653d713453b438f3d484491e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:f535777197e605789abe57c408cf3590f4f2edd96154fefe5167acfa09b388ec
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:27ae2e4f66d04cb0921fce5180fe7e5d055648e89f2a48c4c5d7fca97695d951
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:723e962574a2cd9e2d415265e2e7181530e3704f1a59a846a8652d6b5bec3fdf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:b54887026ac5745a43ccdc21533237fae2c5cbf3c08bf3394a9b10723f9ec5b3