Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.34.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1.34-alpine-fips, 1.34-alpine3.23-fips, 1.34.11-alpine-fips, 1.34.11-alpine3.23-fips

Index digest:

sha256:4e16b4c3468431b5b249d2ca67ba464dbe21751e0a072d35be66a2853e09f012

Manifest digest:

sha256:8bcd4fe0e0e6c8b8d7f6e416dc3827b906c71d206277f89b541ad75399281734

Size

33.68 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.34-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.34-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:cd5f4ffabbc5ceedc12d8ec40fe1436cea095ce06d4654ca37e86fbc47f8345e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:fd4a8c74380769d0f1b2fdf1d5d08ad3c07c3b17239ce8b73d614e8d10ec6ded
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:376ce276d118831ead542f0d112c61966326760d45366a39912e6c34d2dd2670
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:26931a3033e833d0efb75623ed58289bd42b9407d695575c8917fb154510c0a4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:ab72532971bdf027d95b6eee7b2b169850eec9c83dd5755cc2530e98f42fed4e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:8446fa4e2a52ce96d13a03477eabf781c6b67ed1aa5a10e388091b2dbbbd2d60
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:976edbf2ec5f3efd857dd0d3b5948fc7b458126a87d3b07e01ea0dd094aae8ae
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:96977868c60891fa14c67e8e14a902e8cc9e30a3400d5af32bac9d12e416b788
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:1eb9022f9c7476ed3c08167bb8cc507593e28144b2e281f66fff7a340bf5c84d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:b3432f6ab59a9af8e39f3ea118d18b97e75b12e724005f1c6a748b12e0216f19
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:58e1d5adad7189cc1167566e97bfefe1c8fe71f929986987ae34a293d0083f4d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:b4153159476a64f5ba3f874f8fa5579ab722625a2519993fd7b9551ba413b929
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:28a52caf00be9a9925bb6f1e3f1bbfedd360a9962439957d379401eca9bd5f6c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:693cfe1e8a1c31c657c5f0a523e456a1836d0a3f1595a79978c3aec70fda680c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:e6b781886cb38e17a7317881d489116305d07dc183f7e87eee3240b60e33b4b8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:b7f1426207f5c4fc734a809097d1ec0284572dcca624dd65295264a809871ef5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:a0ec24291c833ae7aaef516ab5e2680368bf287959bb9b531971305b416f84c7