Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.35-debian-dev, 1.35-debian13-dev, 1.35-dev, 1.35.8-debian-dev, 1.35.8-debian13-dev, 1.35.8-dev

Index digest:

sha256:ffbe8cf650e5b9b3e43cc14d43823ef1c5607bd991b23f03242b482b05a49fd1

Manifest digest:

sha256:18709a96673860242bf3b4467af452ed2cc280c6b4d0038ef4c0464557a8e8ec

Size

81.84 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
2
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.35-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.35-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:9c53bfb9d04958bf69bb47727bba6e26bc3201bec7f323f9188c7b8074d2a0af
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:669ab049867bc9ec48b406f32bd6f3de35571dd80b6108d9e89bf261ad5ab5f7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:af3bd2dc9aaa115f135cb775de30c730a621aeb46e1f2ef67a7277ea6c98f078
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:c919936455273f5e067806c27c1128bbc1b2d965c5c3a6211c6b85c0eaba2021
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:c28a571d58772bff8eca410e0643f8eab30a8ae3d208b3af202bc7b5fc59dd4e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:c33e55f45ed19fa7914d753c6038d5ef2cd8a8dc76d5e8ab21e7ff293164ec8e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:0cc82d489ecd66ab56574caf91d0a8aa77878b548d3768ad32e1acefc2307adb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:301effc3fc5f576208ac84602ca6fdfa7afc62606b7387c9874fb315a5d21068
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:fb032fadefbb60252c0a12f1f26590d82bf5ac0102db93fa71c841c2634bcda9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:a4a3cebb2efc139a325c7cb1233c54dc708e83b2e77b8824f4c64e77a81bc75c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:cc4d212c9013a265306ab60fa4de4b2efb24088ddefad8172fa7c193f59ebed3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:6d31e7b77e37e1843ca62e0362ba43b5889fa16110095532761b436d0b2f108b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:9a914a5219decfd58ee61865011ebc53eddef6b9705a2407eb7f13cc669468bb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:5afa142b9eaee0b481ff7349b7bc5b20dfb8ad304de4a055d771107beb046ff6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:6ced0581a48ac3a916039068a13848175ab6c354acf220126369d967b4c1d2b4