Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.36.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.36-debian-dev, 1.36-debian13-dev, 1.36-dev, 1.36.5-debian-dev, 1.36.5-debian13-dev, 1.36.5-dev

Index digest:

sha256:9a284d8bc74e1071c6c300db39c771812182c5a4fe7fd22ebe50053159a0417b

Manifest digest:

sha256:d156a029e8f3ca81020a2f2f42e7c73b2a24be24b4ab17ef4a4d09705246cf65

Size

82.58 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.36-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.36-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:7744b92657ed0208dbe1d56612604166463e71d31c5561bc23e0816eff93eac1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:43fb41a70b037f55a8ed1c8be003649f627a4d9db4a9c1b7b8f79e65130d12ed
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:15c61c4fffa8c309257a771915b17cfcea4013e060e45dfc7e13a029cefc4268
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:2654bc5e7c1157f1056b2d369c8687142dc90d33d2fb83da7c392df49d87c40d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:d3a29bb8d38aaa73d28fa2656d876eef76402e2e500d0b55cab8e97fee46cff8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:13b8a59a718491305d3331c133f725a57f58a65df5635a7e4cfdc62ac3ec9f56
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:dffac6de4f5be773da085601dd03726c6386c6c2bb0799c319f3f6e22f0e7c1f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:84ff0b99276e5df24747404abdc913fe575f5021e95b9e5c93b00191c0d77c4e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:5f1a0483a2ecaeb248739deaec3c0e08bc3b89b80b8d615906eedfc4a6e514ae
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:0431f623a0f97f31f9096b141dd4b5165053cf585ca7ce70f284f54827a9e0fc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:40d26fcac0dc6a15785d90cc320cb1a0b1885cb45dc54e72bc56f457f19a7e35
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:9f949e70024e678b15333583222c34eb092dfa2e530d121ad6a9fe9068df88a4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:b57ff8086e6023c2c09b7d08b9a732f3a423bf98717a038d7bfa4c001a4bad8a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:f5977bb5a3d70c69579191d3d6f71cf949bd23d6125df6536d717e9f603dc71e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:5cb83d4713e0d548b2e25fc18d2c89f9f7c873395d1a7ac4565ea00454811661