Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.34.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1.34-alpine-fips-dev, 1.34-alpine3.23-fips-dev, 1.34.11-alpine-fips-dev, 1.34.11-alpine3.23-fips-dev

Index digest:

sha256:9d407c477e6ef02395e827976c540cca639d5ef53a5e3e3d619f6cbe265093f6

Manifest digest:

sha256:2f4cb2e4e381722bd1db2394f606856ef01241a7bb613668a2c11491a43200ce

Size

66.04 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Oct 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.34-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.34-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:c7db08ba298d290bf602d38bc7aea511be05512b51ba6263783d4ede838d9cba
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:e15abe76913309118079bda8d39cd311c3e807a288c0e8f6c07645ec50a87613
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:83020ee748490d022ad037523c4df3d62bd9bf46970b3e5fa4ab7357a5d7f9a1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:45c8b53649010bb64a132f5af30921f29b7996e08912d251e604c55790280315
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:520752af9b524490e2959175060d59a946cf4b9a4726f94ddbdd92e78cb0b9b5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:8235a4d66fc174a93f56dfab3a71be2144dd8b62d6a9a9c0e857fb8b34a06db1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:1f1c8d266af2d0f4d8249781834759a9ee45a73c73d8911cc756386981d59802
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:8cecd8414fa9391f7ce1f32c9c80fc6102e629e6d427f9a2ea5b8c6d6df28621
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:aa6f094f8d656f9cb22819729f0b26b2c5536d239978905473389111dc0f169d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:4f2fe32dae276bc741603ed9ab7dec28a2766bab9c20011f5257f3dc99fcbec5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:d7b32c7547d133ca29da4419d6b121faa38a05da2292d655ad9b4c7d15795dca
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:cb8869b6a4d68202769dada7130b9c250d5e0a506ac17de4c1e315e569f9a52b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:51944af3949e2750556eb38f88fefca32fa8e54943d7e170276fd14f5513aa99
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:a519f5c921ec9c8e2031c6656325a5d0c6c62ab971f4c0374162423b408f9d20
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:c89a444f28827ea23322979dfc1ae1c953f43cf20a2dff2c61f9cf04c41bd833
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:5b4e5a4dbf18e583e2d8e8964ebd788008adcf2c94f0320f6f1a0a8395fc0ae3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:4c2f9d9a591fe3180cf2fe4d5c593bae2f10dd2053c8d770b2a822bccd469e4a