Sign inSign up
Kubernetes API Server (kube-apiserver)

dhi.io/kube-apiserver

Kubernetes API Server 1.36.x

CIS
linux/amd64
debian 13
Tags:

1.36, 1.36-debian, 1.36-debian13, 1.36.4, 1.36.4-debian, 1.36.4-debian13, v1.36.4

Index digest:

sha256:8bd671e863370ad0bd2faa3db3d8a7f0a95bd12acd483414d739cb731fafcf8f

Manifest digest:

sha256:7a3b93336a56525fd47b5f0d0e79927f1a602d85243f23c6217b5abe5eb641bd

Size

26.32 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kube-apiserver:1.36

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kube-apiserver:1.36 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kube-apiserver@sha256:fc0230c038f1647e8b891d6ead7e1f21f2d09633fbcb5a8f87e0ad13cc35e4c0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kube-apiserver@sha256:48f021aea40c39a9d6a9a9101844775a263a70ce7ec793c9754637a38f8eaad6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kube-apiserver@sha256:ac1d48858786f52e4760acc2d3fda14121da7e92f413d22e9e26f702fb210af3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kube-apiserver@sha256:6c9f471797e84866bbb70fc3ebc3affd472ae756a94ed699e8e0a7e440581918
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kube-apiserver@sha256:6ff291aca6c3b52a6c7daf8a0ad30f6a8bc2a6428c2900a2aac34cbb7e291c1f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kube-apiserver@sha256:f5103e798f7d60f7f1d8f9bd35e74b290e632f9ed3da59d30517d663e0e3885e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kube-apiserver@sha256:f4c383de2cf500bd1ceaefee47d14a3d77a7c0c4fe0740521fb8371b456fa3dc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kube-apiserver@sha256:9d13cdcf89dba9e96e720bca72c9fdf6387c323ffbec8e07ead2e85ee0a57e07
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kube-apiserver@sha256:99de598d8fb64dae606040a17534f9ca7c6b622445a13b9e3491b7475970a310
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kube-apiserver@sha256:42eba6db1fad421b03e09caff93722f71bcdcaaf8cfb72c9aac9391407fda5f0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kube-apiserver@sha256:86484c581ff9354df6710062ff7f5ed106d89eb73bf1ac67113bb666cd00d9f9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kube-apiserver@sha256:dabb57a530834c627c7ce8cb09c4169cbd9c1a77bce3ae86dba87aa596538f0c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kube-apiserver@sha256:080251fb44e07a3835a09929423ca45910a43623a8f8cbdd02edb978aae006ff
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kube-apiserver@sha256:60f1a7b94d0fc9e92dbbec05b953dd1a78f2968d9ded847254efa12c294fa4e1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kube-apiserver@sha256:b277ce453afebf16b4389cdeffd4e24970d5b84b99384bc0e9e0a84c325902fd