Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.36.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.36-debian-dev, 1.36-debian13-dev, 1.36-dev, 1.36.5-debian-dev, 1.36.5-debian13-dev, 1.36.5-dev

Index digest:

sha256:95d42b23ac26a6935419d050e895c3caae31a804c2cd313145ef48310d667485

Manifest digest:

sha256:0101b540049915f467156d9b75af44c7849bddb95b7e693fad6627e8a95a24d7

Size

82.59 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.36-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.36-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:534e98c7551bcb9102934b5b9157d9b9bd948443471cf17d51eb20fc794fcc65
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:35c1a66ae56953f91d3a4672daa0354e7e19a25cfe66f22c3333a1e67029216e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:68ea51240e5b2f84ba7a57e47725a11ecce5667ce76caee21a276d0d055e74dc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:c349d4d4917aec480633ce10cd19d9e867aa9bb75274c4ee09d1a5a51575d330
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:d5a59140ce11332fa935fcb82c4eebacf3e7d31db1a035fb36dd33425f7743ba
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:55fea038740af931269d578cef63f632a22f381f4fb5f32bd869d4d0669a93da
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:d2c02e4e45ad5bdf9c358079f49325587727d04a564e2cc0da749dd6618ec0fc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:e18f5a7e414d68873a2cb787035364ae620b8a09466bfb7b569be808a2a9fdfe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:82f8ac669e87fa1ff308d6e4391812e3c4ee92927ae6329173b39bd5f8292e51
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:3b0fb4379d715ae6bcacf8f4972e8ff1e7d68d40d460bc7cb49403f807a0bad8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:fb9503ecef44b9509f79ac37d2d87084310d8aa9f9a7d7e530c9df1d3fbb6156
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:a7536285d066cc7b4118a15496b39a6b37d7babdf8942cc197673bd8c9a32f5d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:d1b8d500d584bb60fdb52cd84c3b14941367deda0b6fd1db4891568d15cb20f6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:da4cd00813ccc88d03cea440e0b7fbf95fabb26f8c764c19dbeb67fb5cafc5a5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:e0e7ed7b86e7e574215edf6ab270c73eef749d3df9f78fc5ce7ccc620a022818