Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.34.x

CIS
linux/amd64
alpine 3.23
Tags:

1.34-alpine, 1.34-alpine3.23, 1.34.11-alpine, 1.34.11-alpine3.23

Index digest:

sha256:c4578498f987b3ba4f45a05682818f296b63e7ce19083562cb0b76d6ef195c36

Manifest digest:

sha256:600625124ba9d0a8f8356458f8a09263d02c3a000b36e69a98987722c799bc24

Size

30.04 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.34-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.34-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:48121cede600e21c0bf717571074cfc4021da4d69d6c0343267cd552b16859b2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:c6fbcf11f4291236ecdbd89fa43a882850ac7da18068c4f8ad420b605988c7d9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:94cb7de28e82ba250eaa91ee340c506677ad23b51fac2f2014f51d5060b2d76c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:e2d9f649cd9ee2002aeef5e2546bc559d242780bdd6f414b52f89e8965c3c98d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:f9d1d387a2601621147d58c892b1bc5577034d48090b2ab06d3b9ebb6e3276e4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:c49bcf5f7ed06f7aff899af1f56a994265220ed907d36d0426f54245b5eaaf69
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:ddf34834a8500534a054849606e20793de3d649770e3800883eba2bfdeee96d0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:4ab1104a91e22449b5a0641f9f4b4855b3a4b4ae23c949694917598ce79d4b52
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:49f9f6d5b892e4e9423b59d16f80d70e11700f7bdc5520a3df3171770a54cef7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:7065530a657bab32d115c72198adbcefdd84420ee1ff38c028e569e8034abe3f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:112158158ee92f3bd4bdc4237507ce67ae4b842333e17421020a7c5847e4de3b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:031e250cc27694bd2a16c1afd65008fe0e543ed14c840da8dea173dd87147ebc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:92c27dace92965b77ab75369d3448b87217fd02cdc1e206fe7fa6f7c5477dd87
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:118b822df67426b77b05dd8ca865201f8ca5057edfbf90a1125326cc818622e1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:bbada84dcbc8608e8f5a28cf5c99852c1b051132e358aa31fa69e98a8d9afe6a