Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.36.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.36-debian-dev, 1.36-debian13-dev, 1.36-dev, 1.36.5-debian-dev, 1.36.5-debian13-dev, 1.36.5-dev

Index digest:

sha256:7a632bc3e929bc203ec2527a06656b61fb6a4dcd4ef8b09cbeea412832f3a37e

Manifest digest:

sha256:7f4002a508c8d82b36f1ec86dc912d09c619ffb5969178bd666eb04399b41349

Size

82.59 MB

Last pushed

9 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.36-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.36-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:65b6d64ba8684da7e9e3459d05300d00d91f6d64f2999d4ecc23ba0483f25b8b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:024c2f13839bd317896692a85476ebc0792d2005f1e914cd88db25adee5073de
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:54d632f04b7e612033e996ec6124110c3ec657e678636de7e1515ac9e7b88b32
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:01476ab0086e3ab41df07e0970f094b0fc9b9e4775346439dab92c948f873e89
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:0aa90571c01bb7f01ae0946923ab7266e119848c99671689b3d5bc60312928b8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:83369f3dcf21d7810799f46756270be0cf8218786e509dfcdca4289dd91d5217
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:5c1af91d157b2e35b6b77d6663df0574f100786e79f657058f05cfee60705455
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:7a81e2d074010154687e662c8cbf48c196f3416a7383e57d8b3f9de6764c904d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:1cf779e79011c98633174688381c902fc59acba08419e13593e4a3406a0048cf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:1b80d900f670dacaa6d9ef92d915903a3cbce6612ed250f6585496374893a3ea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:7a28875140922c4b85374b46c4313e2d3f0d26eb407dee17084190e78d8aa13d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:6ee3feb9c5419f87849e71388a72d7ae43b4c944ec8e4b20b560884914fa5c6a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:b0cbd4c80fd74459dcd81ef9674ac9995fab805ab2d00d802894dac155f805b1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:aee3c75b04755656e846a3a39125ef964a9332eb5ba99ce264d9a43ab55a2add
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:722d466efab0a3625709f0e165aeb237fadf4f49236fa4d808b86b50a97e14f3