Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.36.x

CIS
linux/amd64
debian 13
Tags:

1.36, 1.36-debian, 1.36-debian13, 1.36.5, 1.36.5-debian, 1.36.5-debian13

Index digest:

sha256:564828a7e461162bf2f5d0f517662c02f56ab5e69ec280df6172918497dfe0db

Manifest digest:

sha256:e4ab95c5f71714aac4e3700fe2c26a158051d0274f652b6e7ea3ee5492697091

Size

29.93 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.36

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.36 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:c07f5f2f79818f469f453259524350a0119ff5a7f351209aad5e2b2413248930
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:9a5679c49ccaf26201acd5e6f900893ad3832d446b1468872173b207754b5dc0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:efb7dde9b10d166db88cd47caf51785ec63ccff675ae26122b4f5dce04669816
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:e8085893b5fc4b8e6645f1b8d9b0929d1b07bc02a4b002b66d43de7abc5482a7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:be7044c65f8240e328fe098f3a3fdf9d41c2a29eef6d2f556c92414f87d46b7a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:2ff7885309a814d50b5010a3be3f209cdc1736a43a43d251f63e87c44656c74f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:79782105b0e6983501127e5142b151b4d232549defd2676264b7368c70b58df4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:f64be8e51dbac5d9f9c8882a3ca508f4ca00732f687791ab8e80e50126cfd3aa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:aeea989ef0d08588e1b53031156d2929c53a9ac370f61e34f77369ae2e4a0d39
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:68bed75679be4566e2393ba7da54761aa0a5363326de7af82a415bda3bf71371
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:9cbb2d67fa8fa9c7a2fdbe4cc88621467ba97b99eaf1d27f525785424e91b0a0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:93a412e01514c631fa56cc5c6fb98ebeb98ed9bcb4fe929b16ee99c56f114d47
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:ca538a1846ff11a164bf36bba7216585555f201df8549eb23a563101b197becf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:36ff14310d411d247ba208e72a74c3a381d72c3dfedebbdb2077045bdf33e443
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:b99519de3c02c410871a01a537dd0c075421360e9100d0bc6c84682ca3ea3348