Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.34.x

CIS
linux/amd64
alpine 3.23
Tags:

1.34-alpine, 1.34-alpine3.23, 1.34.11-alpine, 1.34.11-alpine3.23

Index digest:

sha256:f9af16e8e31f82e0fc96c1bbe1f69bb4edf1173d051d66cae73cdd764c0bacc1

Manifest digest:

sha256:4303d0650d01a3a585b679dc6b6db9132089804ed29aff3f35b82936800ba207

Size

30.04 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.34-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.34-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:54884eac4107df07544a00b9afca745f3d37fbd7ee969684b7b54a8f6e1d3542
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:f7ad63901210105d349726baaef5eb76d8e0b3f5a1a3b1027509eccd69166a5c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:939c1c1d541f2149d309d544a36b378ee47dfbeb4af60a3ceb64a5e2d97a1fe4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:4ca40f21c490c29302e2fea68bfa79000f9c20fce2d2e77bc6b77fea033eab35
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:d943f4916ebd42baa57d9f9f4ea01cfb176106e49b41d1b1cce4eda63141a56f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:1b3ec21d65631da03934c13d39241d1ddef5d1bd61e562c6bc731d9b3634b2cb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:26dc8d9cc14a67a55d382554f4aa087eeb2ab2a4e7fbc9ed25c02a2d852e2a4b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:2ef222f02521d9ac420eb0a6060c0d78cae19a22c962cc2cd5dc36a7618216c0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:e579d143ae650226ea65de4ef2f95e76b0dd76883e0690e6873fd4fd39c1d792
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:c19ad05f7ba6e9fbcb66e0efad71e9456fe818db7b94fc17a1c5d3665e66bde0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:0baac2c0291271a237402a49b5a61a41cf7831b76378fa54dd15fb75372eb626
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:e88855503863c985fdb008ffe0b155bcca5d2119b909bf0ce88d690b8bb0de3c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:f3dec93f727d6ffff7a86f090f2a7842807655358ad16c7d8d7744b8b896eba8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:947006381fe9e73095791cbf9dee8c9f2c20ff433422e06cfa9f833ed476c07d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:4755dc3858ab2de11e30afd7db5cdbad95dcaf4cb54eb3c096f6c0f5e315e10f