Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.35-debian-fips, 1.35-debian13-fips, 1.35-fips, 1.35.9-debian-fips, 1.35.9-debian13-fips, 1.35.9-fips

Index digest:

sha256:a76719f65ee718f417b80e8cbb79cb9735968ce4271a412e6c2903c8b400a4d7

Manifest digest:

sha256:772db89b9dd7ed08a498c54bb5dcf6509fd4a2bc3c84a52d8dc67b895f8d1e88

Size

37.79 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.35-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.35-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:96a4aef96d8ac154bfae2209475f55eae1d4cc10229775f755ee1b4f6575fa77
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:1f3163c5692511611d8b32095ac0223d332591edf010a1fb4d050ef835598089
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:dc3919569687b47b292747cdd9357285266cf2cc5495328bddaac1e747ab0cce
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:94113f8fb5164c6ca1d266d514cea367d6bfc25586474cdcba4209351267f74b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:ea606aa9b3f46e2c444bd4d9b17c5d9cf6aa37d04c997ddfce0663f2a4e9645f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:3f1eed9990c09702f6f3c0266a136e4d5eecf93d97fd42ceb35e344461bba4e0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:e6bf98d068cb0db3e151c62812a04f7b18e46286eb87bdfa10575c053eac9317
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:d7741bad73b51715281bb443bbb75cd50b85c848874b271d76d39c02d6a7ca82
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:defb814058b17853185764df89106fab30da5adae3a02bb93dab058efc3ecbc8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:4af80ce829fcc7f3f0d6ad25da8e2c18f57b85426e23868cee6f37642a966575
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:92e380d1a70e84cdd88f1b290d1bfe89218f4b16c27f28678f586d8e9456e270
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:02c3005f96ea02b040cb278f92dfc7f148dabac36380f84bfdc02e2d5b2b7d0a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:d743b3d3d6d728c4f8ad5dfd26e4b09dadc8e35e469f9b00269c76fac7e2fa7b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:5c8b067a111a09ff6f68d4fc39883cbee9ef151867f4c4345a36364cf1083f68
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:c02ce571909d6e60cc8a323ff178584cea78985eac88a0b1586b1bdb4aaab10c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:b4d91696d5cf2ac3308186e6f2de99a060e2e9c5c801cf8efda945fe8c9f7be4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:2183c67b06113f326b9d70f5efa3bf1233ac42c1be4eaf84c0c699e44d9f917c