Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.35-debian-dev, 1.35-debian13-dev, 1.35-dev, 1.35.9-debian-dev, 1.35.9-debian13-dev, 1.35.9-dev

Index digest:

sha256:7ae0dae190a0ca85e54a3d1bfeca8a66560abd7e192c4e46df8d66d96151904b

Manifest digest:

sha256:abb5eb4bb0a5ae2667164ba0b6425b95b5ba3bd16879986ed2a9765716086e5d

Size

81.89 MB

Last pushed

13 hours ago

Vulnerabilities

2
8
0
1
3

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.35-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.35-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:cca68ff314fe8ebe478f8a4252266acee16ee9f1ce2c468b979f4d416fe5d3bb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:bf54223f58484657eba1841df93cdd3582c0f922c2dc9cb7713029a7957b8474
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:a339da69c342a6ad77923d4dfe7af81601bd6add0718afdab3509b0a304cf896
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:07a322df9232f58296714b4b680d21b553553c05c0e8524671c41e6bb36eaee6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:c4bbe2fa8953e2877a04e9713ef1fe608ca27c4fbc3b7e3cda4c7947f71606d1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:12d5323968715f2b5b57ffc01eb2d721a855e2084d65ccc065c0923cad5db3d4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:335069255ac4b009a28672451ab412db8342d5571a78cb65a60edac21a207386
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:504b5deba821bcdeca8b90f17c71b198cf3bd0a72f4b43023cff47c18982e35e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:5c42e9cb3844bfe5ba4528d2768534c4c434d45bb21ac2ce61cad7dd848dbed8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:3223b007857a5629f35848894879a9f7da1866227a876df532f8aff6d80d3615
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:b9e937da6f03f339e3164f1f7fac6a21192536e5bfee8dcf6708e56ab73da92d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:ef6e24aab08719353c6d712118adb2d7fd4e0cbb1a85810d7892532f51160627
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:9af15b617298cc9e0c26d4ac104c7f819522feb04425a8548f7a9f5fce96d5ff
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:ac85f0f28affc5bee7d928b005eb1ea385cdff0342da69a36a1df61896c53af2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:e24709137fc87ef71f53d7ebb85890e84eeeb0cbe5e39d15f5d08d4f91926fbf