Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.36.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.36-debian-fips-dev, 1.36-debian13-fips-dev, 1.36-fips-dev, 1.36.5-debian-fips-dev, 1.36.5-debian13-fips-dev, 1.36.5-fips-dev

Index digest:

sha256:2d17d6e716bd1d17b4009cb1bb72d9edab38414d7f9a357c922fa2c2df03fce0

Manifest digest:

sha256:b17df0e0fcda080b22abd103058ee6f99ef6d1870d9e9b353c3b37cd96771a94

Size

83.37 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.36-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.36-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:bfa584ba0868864e5617fea8221c590de4e10dae014448358780c405e6cca2d6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:2030439e6b4cb53d766510299899d44353868056cc9b3d08e9c1816aaa3d3663
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:895433fb2f7f3aff9fcd2794526cec8bd1308078c54021728ea79f3052b1fd40
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:9591d5cfed5fbd8e55dab1341b8f5e3f44a9884f08105b0795b2bbd8fe592af7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:8e472eac316bdfc51a4fc4b5ce507cea911b97ec97c40bd3576a06f5d17ae459
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:9a8b69d82d51f19d72579a4b48095b3d8e8342dda7fa1d7f53663b27ff38e04b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:25c98a52edecb6075e5346e06c5db2ab33ebac03703bcfcb599508ad5373a447
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:9123f32c24d87b27e96cc1a639ea86e92a2b1fb453b76edb6d40d697f103394a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:bbd82c439758c1f8e6dac5f0e4cf74fcffee612e75208fab4ca352c78e245a0d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:715407f7b6e7fd97ac771ab343bda267be2148b063cfbad251ad13dd0c314669
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:edcde35dc58ef6b25583e27c95e94b2480541f9611ffb40d3839e254f6c090f6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:6b7a3b5f648f012ebfcc6efe8a8c493c6ef9ac6bbc6ad22a1e3c54b56027287c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:091279461150ecc5e6e56ee1025aa77a1d7c0ca31e910b44e2515d4e5166716d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:0f032ff1b801635e793a9249a3eceb5ebc0bca8bd194b29cec9edc5ff3df6c19
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:a3b4e1685891e10e6c1c37d41a80698ab2ed77b7c19cd5470dd78a9aaf039782
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:f6586895894d95c22c35a3f8267541b2ac5d53a7e1ad5822b86760c3b29d9587
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:da8e5676dba7abe352b526dad896811aa6ff202004b606a6cf7baa438c98b32c