Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (compat)

CIS
linux/amd64
debian 13
Tags:

1.35-compat, 1.35-debian-compat, 1.35-debian13-compat, 1.35.8-compat, 1.35.8-debian-compat, 1.35.8-debian13-compat

Index digest:

sha256:788bdf0c83d316ea081b23391e7d2c98ba4bd33d714cf6f7e477792e413d2b93

Manifest digest:

sha256:489219a0e92d3f312204142d20f66df87c218159bd0df69270fc534cc0ecd252

Size

41.09 MB

Last pushed

53 minutes ago

Vulnerabilities

0
0
0
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.35-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.35-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:7f4812eb683030b0c22d3851fbdc429713820adc19f8a55a5a4e0eb8c3509910
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:c7526d84931137d0d0feea240c7ba0d1c744c03de94542fd1c1356a17a8f7765
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:5c5ededd84d6138ead16d67eaa28713a600ec43abaef2c93251aa8380b2ee70b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:b7783485bdd289fe1ed9a1615e80415d09069b1712d017b021b49f9b8b1b81cd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:cc1b0b7089888cdc3953524d0bd142388a2c27711d5942b2662b16201717d9e7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:3f68f8e4a61a8a422801c6e893ffefcc02c1c5d590478e495a2a5652c4da2f01
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:2aaa154a08d064275d42a02861dae80453935d5c7345599b0f52d92a817d3e11
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:f727e5c411b29dc15792d725ac86699d2cf5ba3870a01c09478477cc57e9a6c7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:d7c4cdc248fc62a0b8d26cce03ad4a9e62a2b6350bfcfc73c3da9fd67332c97c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:9a5b03d4e1c4235b0acf73e2bedd8cfbf180f4653a0ffd2181711880e3f30882
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:445521da9ca16662980b425d991357f1216041af7bcfc4e54bcb53d4274c3f0d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:9b71c802c292bc460706bda050d4f9b718de6dc5c8a6ea2a99c3396b9ebdaaa6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:657dbfaaab6b024d6afbf6dabbd420379ca84dad54a6692ffcee2e35ad6a5b28
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:9b2354f3556203363b828d93825e9f65efe7b1deaa71e01500697312cee9dd7a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:c68cedfd2449937c9ee94f4b3747461300306b9f91e94c197aa669ed8642df5d