Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.34.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.34-debian-dev, 1.34-debian13-dev, 1.34-dev, 1.34.11-debian-dev, 1.34.11-debian13-dev, 1.34.11-dev

Index digest:

sha256:016704eba6e25e547ab05d46cb9ac596f729cc86af85420d5a5327af391eca48

Manifest digest:

sha256:9b4f93d3597b4b792a97003a4c4b3d08505194cd8f5a5545422310877d43566f

Size

83.25 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
2
0

Support

Active until Oct 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.34-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.34-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:2633e1af5b9b9eef27cad83319d6679ef930b7938dad9a92f82c8cf96b757beb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:657784210b962363ab1b693ab107dc3d177663213295d2f0feae7b8c794a4ac1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:3e2ab9dfd086ea3cad006ef962ca481335d2e381d6aab55f05f217d3583b0a01
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:a71375809e6bbd796360066b5646ef0cc3518f90c2832f45b004a8523815b02f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:3d1f4f08c23c1e4196a7f0ec36a5ddd2647b46d4e66f7fe5fc3a4526d2749747
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:dd48eb563508b0d92099b9cdbaa84e02f96147a86fa9332c18f65c2d52cc2106
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:862e3849b00fc66542d7833b74b30d2131e91a87a311eae9df7eb0fa091e1291
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:8a05a061cfcda473966e05e8fe0b560362cf633a7d9d9921f8228d766ef0e751
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:3fceb9413d6c6aeb46cf5727c4b6f53cb08b4066738a105fb0364b63b49be6d1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:e1df8d61807b296ae03ea178afc13b98e35beb34c80a3b02b7f6b480935ebc25
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:77b6d808134b7a1281d5fc76dcc60a51126366f820edbb708ce8f3b1f74ad750
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:411dc153ba857913676f5dd0bab9286c4e39c386a21f77d4a7dddd3b74f2949b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:be78dc07624af37090a0bad968f226c89c29941cb0d52b29704d8cdbd9e0b10a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:cb20d37569b49f9b7022b4d0d4c57a02f4c5787b0ca1fce07a5f722a769aa14a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:5dcdb9af8a9b4bc08aab273d2fca775247ab1509e4712fbff54cfd93be5e5a21