Sign inSign up
Kubernetes API Server (kube-apiserver)

dhi.io/kube-apiserver

Kubernetes API Server 1.35.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

1.35-alpine-dev, 1.35-alpine3.24-dev, 1.35.9-alpine-dev, 1.35.9-alpine3.24-dev

Index digest:

sha256:06a584f0710214ec10ba2526e09d61e2aa82b22cc8e46608dad5a2e00d5eb458

Manifest digest:

sha256:d16d3631ae99e9e1e057553f4d840766b91c8d84545df05916ebb7f55bd393e0

Size

57.21 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kube-apiserver:1.35-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kube-apiserver:1.35-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kube-apiserver@sha256:e62d0f3602098f1047e62a3418796df00e18b05435485f205160d6a4bcaa8104
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kube-apiserver@sha256:2245f1bc7addf23bb7cd48f007c9be4d18814be90f17cfb4c79feb1b50cb180a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kube-apiserver@sha256:e0cb2e6f53e5f8d23b9c103d2fc0e94d31915e6ba39d0c7a26a7f60d18d9f59b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kube-apiserver@sha256:538efd35855139705218162e1a24d19cd4fe636746779a10bf48a1e317339c16
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kube-apiserver@sha256:25d871bcc4475cb854138196d190e9618e5ca8413ea27efc5160b598ec41017f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kube-apiserver@sha256:599c81b742c4ba27901ef3497bfd2191c5febf76878622fd0e7e1bd0960718f5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kube-apiserver@sha256:6d9251921cefba70b3029d7f333e61ee891f90291a3092addebd73958488cc7d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kube-apiserver@sha256:edccac0afec60d07cefd27d4a5506faae120fe8aa6f493e96870c6d53a1879a2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kube-apiserver@sha256:34ff9f6bcb8ff9f54f9dc176c87651a55884d662e8430316f3a9a455c81be6c8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kube-apiserver@sha256:022364c9dda5e1173e32e320fb385b38768d42a5143e072becdee6fa8f3f8046
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kube-apiserver@sha256:8c50580d8becf6483b6d5a00d204864c588b2f11447cac899c244e5531d30e26
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kube-apiserver@sha256:e8ac2f72a6479bc5991f7a7947e6b655f105b5ddc3047893968754ee9d9571c4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kube-apiserver@sha256:de3eff4402ed1b985a1ec2bf0552fa580dc2a0159e6afae68ce49498467ef0f5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kube-apiserver@sha256:ec445a625e1aeddd8c9e5701d822851f0d032774f53b6b8935f3b74315621105
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kube-apiserver@sha256:4c0dc7f2ac7cc0c5fd98f78fb39f85dbf7579d93f877bb8b1f3087903177e727