Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.34.x

CIS
linux/amd64
alpine 3.23
Tags:

1.34-alpine, 1.34-alpine3.23, 1.34.11-alpine, 1.34.11-alpine3.23

Index digest:

sha256:dc929c655eda3d1617aba882efff66e6e0d43c9bf2720d9e2adab06f7ab0758b

Manifest digest:

sha256:a551ed72bba923f77343bd8f40df99e42fbd64080a6fc8969e37e0dba323e143

Size

30.04 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.34-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.34-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:a73fbcd14a1d27b55d10a6f551f749a35a39e64d4ab6a9a9f54cfc866173bbe1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:51042736430bba17e89be1ac2aca04c688ad624a80d70fb1c2dbd27eb10df308
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:2a47ea36db03038228a10a07fea926e61a3dbbec8f4b83d30a8e8204caf4a057
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:cf3bc8b14cbdc463b771586afd4a3d0e34be8ab9001a8a8dff1beb90355d2c97
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:979a6ac16c0c9f0e074635a740ea373df2f4995620094cf7f4568c0c126053d3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:9075a6226dd354740b3ecd2fc50d3538e0139432c74927b5dcbae49eae1647f0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:7b918fb0e5ce453747377dad69b5d40ef5b1f87fbe699c05e84f3f411733f94c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:0d2428f7224206c0e7e64532f014edd8cd8483416688b20b7628359db8eefc7f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:ee68fdf0f1dae6a4ba8b07bfbdf4e6fb890da706f72ebc11b237f490a072e2f0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:f0f80b2d55288e4aac6d55978cb2167cd46fe9bd4e14a846fa65f5c09b111f19
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:bd328c8efaa498cc64f829b129a28d6f8f8f6f6cb4e838ab85a73ca48e917781
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:c147ce34fac9e32d7529300bd82c38bb177f31bcffa13ae78acd909bf1be1871
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:f36a8fa07983b9ec4cb9d33c6916c81e08339b82c19ade646e303574b470ac67
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:77843c5edfefa0675332d2b66e0b0161835cf20333ae38e1913b8e91b6bda456
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:0540a00c101fd56c73edd2af83d3f56330f2ea5ba2122b6fe027a5885ccb38d2