Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.36.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.36-debian-dev, 1.36-debian13-dev, 1.36-dev, 1.36.4-debian-dev, 1.36.4-debian13-dev, 1.36.4-dev

Index digest:

sha256:1514d267c68459f976baf78c1464efb7fa2729bfa0aebb90ff1aafd44b11b772

Manifest digest:

sha256:7f4fea8c3955525225f81bb832aa6616bb38b7f4c3f2f6155784dd6c25914bb2

Size

82.55 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.36-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.36-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:430e98787fe67fc8097d24e663363c2ba719bca6238050d18010f210298351d9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:ec4da8bd984b0797317a1e9c3d1b043e369f8fe81417a62863efba32ed4da981
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:5f425d307d383eacadc3e0798307241f123f1ef35e1e34877b1bfddadcae6dd1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:ceb3ef7c6195333da16ed6e779becfa2e9cd3fb90bc5707c30916a01d67e1e02
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:b00ff5f2dcb6f81ba9e5545536256ebde284eb6991019716cae9e316b84d5610
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:2c11e1725266602560c9abe6545ad7025eb3476c7daf9381c985bb754adb698a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:eeb79a19af7fd1c94d2237eda1148505690a5f6cc3528d270fe13b418ea20ad7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:a20b4ce4116167f34443383d85fc043f4d4dbc3f4de7d6a8ed7844c4dd43dfac
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:3e5a852ab396029af26064d9be4253c1b9a664d848f3ce454f3542592d128870
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:7c2312f2a5b1a4d0b60111a12a75fff210fbbf28b9bde7981195a21f500c6ed1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:ad62a511331244d0d803ea19c36f29ce15c4a9ecad1f2191f2ebdcbb4bbc6500
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:5158534311db0555ad8861609a25d5cc24a14642ebe9122ac80c521df5956741
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:17556d96e57a227525e12a3397da9aff0d91ba9d3014dd3d34465889b0fc7676
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:c68caed1092d7e21e821221f7517f11a938f0529031a78db7c80f6f10ca0acb2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:a4dbcf4ba3d781089e72565b5d324780dd79da0de2d5b5053682ede0c42c4851