Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x

CIS
linux/amd64
debian 13
Tags:

1.35, 1.35-debian, 1.35-debian13, 1.35.9, 1.35.9-debian, 1.35.9-debian13

Index digest:

sha256:bc97ec040069408e06477d56732411a557e5a1cf451ae87ad3c364d7760be902

Manifest digest:

sha256:ed0f4b7285c7ecef2f17ef295f1904e0b9f136237202016229bd4aeab9c1d769

Size

29.59 MB

Last pushed

6 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.35

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.35 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:e6f8a555a36959a2b27381154ae0e0c6e6967e1783db44fbc499f27e8d35728f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:b6daaaee243425e525758c186742da22c817bf260ad8012c4df75c27d0bfbeca
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:6d58094ecfad9455b7017dff02df79753172a26a66f84ca2974c1873dddacebe
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:2c136088b64883bfaf3762d40864158938f928473f635b1939c60b650c7cd163
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:ad3427b308d1eef325d6143ef1e3f0e2da6834e2ade02af3e88c3b5503fa53a3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:8a509eff2a329ae251d882f4c5f15b00022d2e10feea3a70f7dce037f06b8b17
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:edafb8699b29e11fea60bfb0de012ca780b4c1966948d7f538a839780c2b2b06
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:b5039379fe349856539334124b3cf3048f357e35cbb9aec7caf61716f56001b4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:7d59a175f5c512672b82ec0d2419b0dcde914ae51babda9624d06b48a02e05e9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:4e0a98d7fcf19a1e571e7b65bec6be08a340f24654405c61710bed3a86ec434c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:a171a0463f4fe5e65b43e8f0f8826f4c79453c3defdd3f29b620f1bc685c70e3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:a6b7bcbd5ede23a8e3c73b9d5672ddc9e215ae5c2219b66a0f1dae5fb6ea5149
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:bd87691c5af82dbab026ac4e49f7c43d100f22da466642d6ba53c283d4340e64
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:f6de467b19e891ae149fb2d213ce470887d07d2fbbe10bdf391691e1cd3946c4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:b7842c45042da948972faa1a7aef9719acd6504718f15c6f7cb27ee6f050e271