Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.34.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1.34-alpine-fips, 1.34-alpine3.23-fips, 1.34.11-alpine-fips, 1.34.11-alpine3.23-fips

Index digest:

sha256:e51ac2e9bc9c6c961b0b50851f2eb4a15a6b926a185046a254e1360db3e397a7

Manifest digest:

sha256:d628b64393be796e0a189d7b5b4f54249ccf266b4630363097aa0621b11796d2

Size

33.69 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.34-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.34-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:a2554ed97913aaa810419c2dfbb572970246816e20e6f1d9cb69392412764ba2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:6e8d054f76968d62a4347881a770015c73fb5825e75a02f3ad4eec00098adf9d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:3bba7b9dd31dab72095c4065a1118dc8208270d7216723c30defa1df4a568bcc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:0cae38f7f3db3a2930713e1de72eeddc6b3a52be101769c9c787e486549f8c1a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:12029b4f85e96b879660cf8938338ea865e7356b5d107008554a5470cee9cab9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:36835e0d7f35a2f19600b7011ba8a36101b4afd5a9cbf86fd3b68c94f399b886
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:a13d911ec2a3c1c0ffbb55d01bb1b7d62adcbdc60bac000730c0460c9835b771
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:94a74086e50439ab3d41fd3322930beb740ee81f85a0eb7ef654e69fd350bc83
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:296fa6dee8588656275c052e0de0ed74fa3c10a6efa25fad0555dc5e465a6e18
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:473db63e60b4dc47c289abf424afe2e1a718ca75502fafb27ab0480cd1b0f56f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:c7b187f2b48415ec1a7308a5ff11a45c4091bf6ee4c66e3946ac00ad04a2e5f6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:ebc2f475dfd918df422ee522502e020b11a37d4c8aff1a0f92bf9e27082b33a0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:3633370f7c7b933aa37e07723a0a0dd40822c1b3e246b8ccf979a0349ae80faa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:57203a24c05858ab8702292202786a46a1ca0bd25962375141973df50cacb6cf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:0c21affe3c98a8ed565ee0fda903603c952064fa9ebd770824c4d7ab2c288758
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:5fc8a77f3ed08ae0f764c1bdc53b78b2d288fb19b426b749d5e5396fbbd8ec64
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:db8a82a1c4d062f2ea0e38cc861e1637fb7deebcd7674afbdef65f6b0c56a8d3