Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.36.x (compat)

CIS
linux/amd64
debian 13
Tags:

1.36-compat, 1.36-debian-compat, 1.36-debian13-compat, 1.36.5-compat, 1.36.5-debian-compat, 1.36.5-debian13-compat

Index digest:

sha256:de5e855547b2a6f9eedbebdf1550e49dd5f66c5cb9fff56ee7df70653fe4a5f9

Manifest digest:

sha256:83ea5a84db934d2560429ecca3afbc227254fb5ae5e755c8cc4058e4e1b839e2

Size

41.43 MB

Last pushed

3 hours ago

Vulnerabilities

2
8
0
0
3

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.36-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.36-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:221cf987db95c1220472f35b1996846ee7bf1674a38192d39ef48b242959ad2b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:f115347a8b25300403e283313202cf3c2c6bec458206d2caf5138355778e9b8e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:de553db48311b26a3a324e08307a3c054b0c40ab6b8237da16a22d88ffca1bb0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:71547f5f6cdfec9cb900df761e1aa04c78b4550af2a06962a49188acd7e66521
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:524623c661e0546facba06da49cf35ea9fee42dff3cff4afe3751bc05089df91
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:e8b6ddd4f9ea5859aaa6ae9059c67aa605a443f8c8bf87c8ae55db6f9c1ca51d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:0e2e52d84bc916b1fb4ea7b974373af2ff59afe60d61b5bbbb30f33bb3754595
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:ebacb60d713961d50bc047dcb186c5ecc94117622f790228471821a335319fc3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:e83f8c17ac96594b78f7cd815d1a7246c75cc949bca2c9dab6df08901487b053
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:f6115540f64896ffd7b4fe0db1482fe653ce98bd33e81fc27534f2e47c4284c3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:e83fff19962d37af632e28f965e2c9858c01ade480a50ed2dba8f7abdf392f57
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:d3e27407b679126bbb57977bc5039b71ccf009713f1a8fdfc58c71049a57dd43
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:42d4846b87e972116c06355d3f8da92dc15cb235d6226f50049bfe3750a55768
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:2ebe5188bd811a9545c622f29072b378cde113a979c025a7263df1dc9638e6be
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:97b122aa1c644062effe38c138a0ee8432eb015862af540cc71b80e6d80a8c09