Sign inSign up
Kubescape CLI

dhi.io/kubescape-cli

Kubescape CLI 3.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.0, 3.0-debian, 3.0-debian13, 3.0.48, 3.0.48-debian, 3.0.48-debian13

Index digest:

sha256:be8368233e8324b9bc48006a75df131a0694f16d44d161234a642201bdcb7626

Manifest digest:

sha256:c2f8801c2faf03ffaa9f73fdb90d6540e71661b8cb5fedda54f0b378adb71df2

Size

44.68 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubescape-cli:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubescape-cli:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubescape-cli@sha256:cb7a71fe4a25794508c2ae886a7984b6d1ac813125b54ffcd273da71c4302fd5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubescape-cli@sha256:bee2eb0e31ab3eba1ab929e322b875a57952d6ebf2335f4e216e281372968c6f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubescape-cli@sha256:88f2d85944a094bb887c078bbbfb840d8a3c83b1cb4640f05bf8cc198e78ff90
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubescape-cli@sha256:6ad01a3495f7c48e50664dbb289e3c9cd1b03dcbceb5f4a2e48706985d858f09
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubescape-cli@sha256:127dc950fb1eb1a6745077a6aaa620c2b2d398058cf3c9fe37c177095ec8aa1b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubescape-cli@sha256:a87b0fa808b0f5bea1a7a0e063d0274365f85455c5cfaa5d8700e4004dbc98cf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubescape-cli@sha256:b03064442618f053349a801ee52cd620e9013de7f4ed65d81a3e589fb552387b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubescape-cli@sha256:74a09a4a7b9be94ebce33e0774e528d274ecc1e2b5b1aba254e7023049ff3ae7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubescape-cli@sha256:3beb39c08f0b42f03719c0d0d170bb2cd8c9f026665584dcefdcfbb9478f40cd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubescape-cli@sha256:e7cbf431a555798834b94ce6bedf153bc7a902e9b45c6b49e2230179ef4ae113
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubescape-cli@sha256:4950bc6fcb022962ee7281bd09b66533ec9ec3213ed4143f1e7c51a5bd9558a0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubescape-cli@sha256:71cc8a19f3503d4a1e05b88597e2be6a5868ad4ffc21e658be393877bc63dc93
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubescape-cli@sha256:3b7a4b789b7c098e8393fccabe503b68ffce98d7407c7b16703aacfeefd7ef74
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubescape-cli@sha256:071f01fa4d0a937f463769383317299d4ff09146e3dece84a794f489076af538
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubescape-cli@sha256:6de1ef2822689b2c34fee32099467aded4713e2f2ab224d19cda0065ab5d27bc