Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.35-debian-fips, 1.35-debian13-fips, 1.35-fips, 1.35.8-debian-fips, 1.35.8-debian13-fips, 1.35.8-fips

Index digest:

sha256:476f518840da05166cd919db2eaaa2868ab8999cfc9e8c8df5d0bb8bc69796ba

Manifest digest:

sha256:b08b1d2cf909a32295753d9408bfccb5f626d93ed65b2d048d09720a7d333037

Size

37.79 MB

Last pushed

43 minutes ago

Vulnerabilities

0
0
0
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.35-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.35-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:f8220ad18515f79d7117abcb6ee621364c135091a52712d2b37aa4eef8a0eee9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:807aec02fe50b6e2d85d100f3adec2e5fbd04f4190c89ad5367582b385a7cf60
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:41be9415e3e437a7cd771e824312b2583bee56cb4a29dbf42feb2316e01a08c2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:139e76e0b056a1b5aab60bfcd5669c4ad4284f09b228b26aa6222bb147ea2c1a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:7a7eeddb11185125b5a29d54f50f2d72796b044ee19287166363fa24c18d409e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:230150d3806b96c16c6c696ad0a04ea5184a16240f81d3ca93a9def26070e61e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:3ba19b9dcc079f76357a838d400f9fff8d2deaa59ce292ae52fcce734b399f51
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:cef512d194a340e4d96172f6836ea34796da7bd1ec08df9e9a52c33294bccd1b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:f4ed4d3796d72f31ee499b79ae173e3f8284f576ede9432584c0e7d8c5e23701
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:db85fa4029f297f9c782e7fc6053d273c716d69e422e8462c8756ed983aa449a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:a3688651daf5cd794feccef9bbc84539d717a8b941f9ce62bbb412200494bb42
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:c3b274482c4770bcc2c2dc04b25016407cbcdbe9bdc6208aff3b319a0ff9b19c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:1df8efe261056d7e3f3c2af37997edf2727e8d99b4b84c1046a6004d8bb3570a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:2fc0e78d4da52f6c90840744969d6bf59be81973538728ee0946671db4307314
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:71335dc89dc34aaf3dcb24d878ac3ef74719dde0b61cb25f0ee18432122c0e8e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:6f156d53bdde8bcb29e52b23cb3e386834bd71897516a460aef4ae150356a4a5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:9bcfd2d18c043bd85854d3e220b77e3cf8779e96af434f0804fe0eed31181dee