Sign inSign up
Kubernetes API Server (kube-apiserver)

dhi.io/kube-apiserver

Kubernetes API Server 1.36.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips, 1-alpine3.24-fips, 1.36-alpine-fips, 1.36-alpine3.24-fips, 1.36.5-alpine-fips, 1.36.5-alpine3.24-fips

Index digest:

sha256:ed85b96c27777ed715593c7f4c77acefeaeb45cd583fa7a5ada52a5f83ed1b10

Manifest digest:

sha256:bfaf1690d402726d4d64b31ce8c303feb9a052a80225bfffdb65ffb88002ba15

Size

29.46 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
0
13

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kube-apiserver:1-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kube-apiserver:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kube-apiserver@sha256:d09dae89466375364490ec00f1e2031c2ef01a4173afcf09e8409058718c2249
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kube-apiserver@sha256:b8dfc18c67a6f10c4cd68ee7eaa6d34630e2df60c45883c831c56668bbb601bd
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kube-apiserver@sha256:d00fbed5fa559511285295d09a0e122ecf39e3da1e06b7c532da72fee8a668d1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kube-apiserver@sha256:d4c7c6b2597ede0650320273b836e477fcf798297e044e165e380eed8f787a03
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kube-apiserver@sha256:5bed675b8f03cb4b472c1bdc2e9287fe72b7644d2c0b8b72aa58ab9d5bc010ae
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kube-apiserver@sha256:06a0cc571a1630bf1afb7ba0b5428dc7b0504405d160e3f8459df6765730ea75
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kube-apiserver@sha256:22580bfcb76ac7fde89ca0be7e39252cbff2d0a67358952032ab4261f792d2f8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kube-apiserver@sha256:28adc157f33fca8ab6df36d9cdd9559f88c7adc42409319f9a35adf3506a4b52
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kube-apiserver@sha256:5b0ce55c63c15e7bafa506e1f935de57c9796819a8a2fde06db860baae146d36
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kube-apiserver@sha256:0b78ba4fdc758c8cd4459bbd66d681130dcc0e39e416a753948b2ea5aed58277
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kube-apiserver@sha256:b972917475f910e62b219d5c67cebed899580075c3176ea42d27d305898f9233
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kube-apiserver@sha256:15b0973142216018b5d44742ec5d3ba294351cadbacd061ada9d475c2c5e7e24
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kube-apiserver@sha256:5b6179d1611af554a3ef47d48815423672b3c5d95251154877bba793b45fa9b8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kube-apiserver@sha256:0b258ccd4ae8e2756189e8baf673a4eb2508ad4b28e787de3a79795a55fef91e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kube-apiserver@sha256:c59755cb8530e05e30eb8cce21c950a836fce87b80b313ac5ab8a05876fab374
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kube-apiserver@sha256:48048903db6d041d67a7e99a0c9c179fc0b70ffae0566a60bb4661105a8c269f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kube-apiserver@sha256:2e1d859fa802759a7a003b938ff4dc91873c92e66bbded6289d1341fb8191311