Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.34.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1.34-alpine-fips, 1.34-alpine3.23-fips, 1.34.11-alpine-fips, 1.34.11-alpine3.23-fips

Index digest:

sha256:f5a6ff93a4888ef87656aabaf78c9450c146c7f5b4d952f4ba65431edcbb674e

Manifest digest:

sha256:f56d649339d7e715883a4df6d6d0373d573e274ca5bc87a0a2e8bb854c146803

Size

33.69 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.34-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.34-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:61d8cfac8b23ae597a7a7c72bc123a3c33bbbbdda1d4a0a2efd3634a26e7ca50
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:50562085637cfe3da7f5de1a7d6bd6d7642812faf3bec740670f96dd7390426f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:993f292d12b4129af162fe2a1208f9d9f5117b06d1e7bec7b015375252c65e53
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:3ff102269aab948e33fc5df51e9bbf7d7b161326eef1928a46dbab9af7ed1e0c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:ea98ca8f69e570b29b128b2953842d2584687e51236a63dd46cb2dc62f928d38
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:a583c8d758a9f4df79d87bd7990101323a8ea4b141e406e416c4a429edf81737
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:971cb7b66a3966d6cb2ca26c9ec127393f16bed9606529ac03099e2556ceaa8d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:c92942e8dda42f39f9d246246313ebc6fae7913d9be53e2d78c068e2fbadfe86
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:56214a791b84b81ec56278c353bfd835a69780b8e1c3e7159513ee446aab12c5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:4a2c0e02196016c6cc1bb24c713836a10fa0a982ce1c2b76c51268814321321b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:cb6db8b64176c8e183f2ce26c8eb13f231901acbd56dbaa531b79f5dcaaa9f38
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:ccf2e8f9832741add379e727eefa4860d60229a2fbe778d231339fea9ba86d63
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:9ba9cbd78ef84d6a38bc7f2ee6f9e93dc46f1660cde1e863fa6f154bd3861afd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:152e054a9b416a4e074bcd9037ae0b13b3d507ee7ff40d2b8bfc5a1378241edc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:0db428f4130d84bc8b7eebfe832906c60575c6efc73ce200214b92fb7e5be17d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:5832eb736e36a46330d73a2f10db9e806c328ef356e0ecee5f3ba59fdbe26021
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:c1279985ecb4ac3c67738167a283603edf1e157d7fc3d77e6148d45a77d2281d