Sign inSign up
Kubernetes API Server (kube-apiserver)

dhi.io/kube-apiserver

Kubernetes API Server 1.35.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1.35-alpine-fips-dev, 1.35-alpine3.24-fips-dev, 1.35.9-alpine-fips-dev, 1.35.9-alpine3.24-fips-dev

Index digest:

sha256:c9fc70fa0dacb1da3fbb9dd0421561158f5bfdcb51cbe330dcd0b290954347db

Manifest digest:

sha256:f55174c9ec34024c5f09a7c83aa2a91647eb5d03ed06656f661ea3f7e7961a59

Size

58.03 MB

Last pushed

4 days ago

Vulnerabilities

0
1
0
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kube-apiserver:1.35-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kube-apiserver:1.35-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kube-apiserver@sha256:534227d08397e66cc4fd8f020497292f3a58e5cbdf10248c8b17f0632a73ef3a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kube-apiserver@sha256:b13945d6acfda8a3068efab24d7e6872ebef9f35d84c95747c349f12258eecf9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kube-apiserver@sha256:3fa4482f0d34d7b1ae59248b4be17842878614a1e844eb9a1dc384b9cd72cf65
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kube-apiserver@sha256:41fa41016702abbe0be019c2e1802658289f09194930bcb88ff18de195ca154d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kube-apiserver@sha256:3118b758bd756647bfba1b604f2ae635072022d4a2282a40ece756c4e3a2ac53
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kube-apiserver@sha256:d238a6bbf7d4d9a32089a409dafcaabd49d9379aed799c727cd04ed1126513ad
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kube-apiserver@sha256:bd923fa63f941f17d50dbf63da222c0afce65db665c2da2e86d2aac9282348cc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kube-apiserver@sha256:02eb55a69f2b6e99884d20e396e7471227cd0989efc054f0f6d58142ef56eb61
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kube-apiserver@sha256:37adc0ac0468a2e0d9e1890215fdde834931e6166ea188d094f2af26b293ebaf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kube-apiserver@sha256:9e58ad98b40f4d9008aabdebbca7010bccdfc767302f3d81c4994874e587eb25
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kube-apiserver@sha256:73eb306dccab62b5d0661b8af16f823364f8b4e6e241868da36e74f9d982d78c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kube-apiserver@sha256:7c13f4ac10a51a5b89a0110d4b17dbefdd5ef04b1a4f5740892139df94035f18
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kube-apiserver@sha256:b9cebc479594e8e67898ce5aabc8fb8971a21186d7c80690df30400593538a32
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kube-apiserver@sha256:eb4f6d72ad004f9dfd353eedce82c92a21f0d62f0a8d14348ff0c120426bc1d3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kube-apiserver@sha256:ce2658375885dc53ef3ec979267d903b733b93db228e6bc8d9af0069e6a0d21f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kube-apiserver@sha256:9f73bf33d1eab5a6fe8f28c94328360a566cc59af3abd0cd0d565d733bc24f4b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kube-apiserver@sha256:71ece335acb26adae60dc82f1662d67bf93fa51dc099cc8a7a7cdc84ddab7dde