Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.36.x

CIS
linux/amd64
debian 13
Tags:

1.36, 1.36-debian, 1.36-debian13, 1.36.4, 1.36.4-debian, 1.36.4-debian13

Index digest:

sha256:ce293e24f43f14e667093307fbac02436b640a80266602e4dfb6797dcc8d928f

Manifest digest:

sha256:c41caf90dee9b8fd21b43d6bf9aa03648e798d9f9dee623bf3b3a9083d08e003

Size

29.91 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.36

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.36 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:71aae6347f208c94092fd772f905b8b9bce0bc16ba6f482d132455570cc3b0ba
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:0a9d89ed3acd2704a2517d2b8c16a47c164a4f3b9a0c1b35a1e7b155c7153130
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:bf8c835d20f40da6019838a97fabfdc27d005fbe3b1ef85e227b57dece221c16
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:b077a7276abc33d210ad6757e2ab4ede9996ba43a7cb2f59c55e169b6edfd1c2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:9895429cfb6af3a2511861a054d9d76868f1efd1265e2faf076e6e88c2123098
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:d616a7939212b44dfea4e267ef7864f0010c6c34b8901648c6bbc452a7a72763
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:233134cdf2e22bdb22b0396d485f03fc4a97d202a61a143771deeb7d119f44d8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:7e53cb2f2f04b1c6e87c49f4f4261da83bd59d06f2a0ba879dbe1dd7b04199f8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:c7891c3bab1d02fe2fa9c2912e43062e932ffabec07ca65ce17442ad7d62c3b7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:39788fee447ff983b27b3975b7a3986ee496dd86f3bc777167537adcd9bb5931
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:327956729a6d4cfafc0d8a64c1f784ddb322387b9f424f4ea89fa4e0d23db262
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:f20e0f307ff6a6bfa61db6781f86b01985f6205b7e7be94a9c64d667e5b0bf08
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:fbab049f974f114cf718c8e063bc40888fe5408e92a90fbca25e77cf51b2dbd6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:c2cde880228c9e6a68164d854a53b4cac24be6c05286b1f9908fc17caab3e86d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:302c894e1cdadd33421a687788815bfbe086e944fc4068667a90040ba5c80860