Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.36.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.36-debian-fips-dev, 1.36-debian13-fips-dev, 1.36-fips-dev, 1.36.5-debian-fips-dev, 1.36.5-debian13-fips-dev, 1.36.5-fips-dev

Index digest:

sha256:3c3cf18dcc1cdd52e90852be8dccd768dc19927f1176ed1b01e3fae6d10be570

Manifest digest:

sha256:13ec9bf8bb51dfd70ca0e0f799cb0867ec3eb6353bcc4d92eee08b2c4782c051

Size

83.38 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.36-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.36-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:e248cc359f39f2c7fac02bcd75cef555d6e865d0ff18eeebc40d897f0f766d4d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:2aedafaaa5f501d388de36422c02af7b844d6264e0317276a051887e79768e81
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:91c2746a231ca70644a726c674ca0f6e0b89d9bb88868065e1fa75d1030de162
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:36ffa3ca5f79b685272301451c66dba3d78a26864a1f23a4de8b18280c665718
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:ca4f60fa66e5f38ff527201024b0c33b01bbb0a641b2f257d757c07837821c7e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:e12012786a2317112ec065ba89698b89fe00f6da33b74d29dbe18707a9af2855
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:17448ea1efda4616bcd5b1eb99dd68890498b2a324fc0740ecd1ca83a3bb12fd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:ae137b1d76fb3be751822c4ec4053cf29b4b4c209d528bc52cd0a3103a538fa2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:6e9035b2a84ccaebbb47cbad3a968f879ecf1274caf7283a1bb5594ca9608ea3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:b933eba620e0c6f804191da512611ce35fbf930aaf45b1524a2e7950f0223871
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:04fd2b32712417ec558ebb3b6abf49d0dce2eb7728d028b41ee9bb1997c632b5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:12061f4c7d655691a9e593a58deb665e9d793c94af3339deee21c8ce885e7742
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:476697f124934bb43186e7bf16518f469c07aed9fdf73482db35665a2ee65702
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:1b69215cfd2eeba652f1917a43e31ce6dcc7d25d7ce420d0095a346ab63cdbb4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:061aec8cf0193d648ed45a4a9754c346deda15bb5d99f4940786efc1322ad7ad
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:061d303dac2411d9eb0a414e9afc4198c671f687e9797a81347f53d67109f021
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:17cf8a0049a6fc2b32f9b9b944e5d02d95c8de48015b133bc09d4c35015a07cb