Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.36.x (compat)

CIS
linux/amd64
debian 13
Tags:

1.36-compat, 1.36-debian-compat, 1.36-debian13-compat, 1.36.5-compat, 1.36.5-debian-compat, 1.36.5-debian13-compat

Index digest:

sha256:5910fc31723b4d2b233430e930adeb7db5936cba61ec6c213158df9f21bbd392

Manifest digest:

sha256:8eb17ae4bd9016cf18528f8df4fbe7de4e9de38695daec8ddba441e3fd9a9cef

Size

41.43 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.36-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.36-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:b0e3c12b3ff238e67716a2b3c3e0ef505fbb33aeda1622a7d7b0d5f5a129bfc9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:599c36452257cece00dcceb99a0a874132744652683eb5d08f422ad4f1503bda
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:bd4ac255ac9a9311ea426cfc71e50cb0f1843fbdc7a84cd84163befac5855fc3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:ac34e9635dc83c0ef1c4fb2859124ad4b6a6e12dd4551815bb236d2d08166269
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:4e0718abeaa95c81ed58341b5790f672b58f26567803d57fba27a4bf1c239d5c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:ef8b9bbc71a6182c3d7f132997a19ade87da2da5a4bb229c2e3eb9601d6259c3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:d8295ba530d353e8026f474b281a97763feda7771bdf6a891d2f35ef823155a9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:ce833b73e886e0d8a56fcd8b76c851b6e492573b270798e19461c5e1a94b1655
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:83d5a365d405f19e34bdbeab367eabe559ac6748ac36fa0cbd5fdef1ff4bcef2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:34d81204f7efff9c89db24b7687c4dbe1db0bbafa7f1ddd2844c459fb207c86c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:97a6b40dedbf5f0363a85d75889d936d3eda0b1e7a22cbbdb300aaceef6a8aed
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:8b01b66377ca6d943f8544d79bdd8c4caa91bcdd5f4b938a3d89f3475d43d73c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:0e119eb4ca19e05c4dcaaf43c0d642fce20228eef68d1529f5c4b5fe7a7839fd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:986dc068c716c288ef8c828fa95c51bb6ea70114b32ed097018a122e43d9b3af
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:b46fffa457541ebc04dac7b1a4fedfa3ea7a5505a00870cfbd9121e5291e3982