dhi.io/kube-apiserver
1.34-alpine-dev, 1.34-alpine3.24-dev, 1.34.12-alpine-dev, 1.34.12-alpine3.24-dev
sha256:f6951f24ccd77afa99575d7c1c79ec8dcff8821e8170677c5ab0d281e11525ec
Manifest digest:sha256:a898af35a4a67d4447bbaab337695541b8ab88a43d7ab1b6142bf9b13e800362
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/kube-apiserver:1.34-alpine-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/kube-apiserver:1.34-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/kube-apiserver@sha256:fe8f881162b70a17ec2857a5147b0f4e6cc20e3e568c1f90bdb4a4b5c8ffe139 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/kube-apiserver@sha256:e9a8f1659dbe2c08d05fc1e955862a5af4bcb0a0b74f959a8d5bb4f206affa0c |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/kube-apiserver@sha256:fbe8e2e47338a7cbe3798e61443553f96cd714a8def144a8645548cfda659cb2 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/kube-apiserver@sha256:70820a9c9174724b346f2c61324a57ede607387e62003e11af2f2083764cf747 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/kube-apiserver@sha256:30a974d2e7f58a338650f02441fe6e7fa1c3d56ada9b9269c72669c9552ad367 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/kube-apiserver@sha256:d0e43bcb4a785292e2b5c67cae204cf37872d512b2ba7266547b54ffc6e734b4 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/kube-apiserver@sha256:c10c904b0b0f7d2848db9849272b6b5d8479dd9a3db5277bb451a9dc0a2b258d |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/kube-apiserver@sha256:141b84e3585f1983909a3aeb7a685d246b0138434eb5e1d4d22ee0af7185b8d3 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/kube-apiserver@sha256:f5e847c5d393541529f44426014a40b8a37dd1d38000392592b8b508277bcec9 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/kube-apiserver@sha256:3db4cec085caacfc7464c0d1e512bf14fba5bcdafa830f2f644c81f74cc6ba28 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/kube-apiserver@sha256:d963adddf3fe8ab3f846d30019c23aac19f4b001a7737597be68e8b87e2bbb4d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/kube-apiserver@sha256:3a5e5b9ea9e609d692ff1084bd74b7e4a884deb190faa3fc87d08abe61a963c3 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/kube-apiserver@sha256:66e81dd2d1071fa774723a42eabbc8acc23bb269271d3a785acfc6696558f114 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/kube-apiserver@sha256:5bb4ac7733bef0af6ade16e3e6baf9e19d5d43b6f5a03359fa3408174d75c4fe |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/kube-apiserver@sha256:957c0c9921f756c487ada2233d37152fca1c95273bc2fa498584b84e7c149231 |