Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine-fips-dev, 1-alpine3.23-fips-dev, 1.35-alpine-fips-dev, 1.35-alpine3.23-fips-dev, 1.35.9-alpine-fips-dev, 1.35.9-alpine3.23-fips-dev

Index digest:

sha256:81a2fe7dd0aad866273215e69219a30320c6d66dc4e16bbea57665f7f2774dd5

Manifest digest:

sha256:1d953c81a93a26aa0e25ef4f76dc0ed79db99fa43262c57f914242142dc79cf2

Size

64.68 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
1
0
1

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:74dee3e09086c3d20f86b674d633c1e3f79f5b89990ca16064de1758fba86d77
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:32161c40e0be5d6cbcc5812e93094275ac78c434d82bb617a22a7fa8792b1de8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:448d4f308e01b732de024796046ef2d417a72f6230ed0a069172cf754d4ef3ed
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:b7ff7dfcffd9247c06a3d9a483f688f1178c51290c1cc34da9486b2daef1a949
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:abd1dc722fa9221828255d353be130e9fc8673078b8592e55aa6e31d10d54c72
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:2ab10fd9d16759e2fc330d610f380c12e7386073f009f969a7bca186d48b2d50
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:5d23d5f379eb16dab34402ac6ad7c73feae5e2d243e9702717210a1d00c9dc1d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:588a88d54f811a43f05a4b4bc0e0048d35729f293982d59920cafc775e5016d2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:6469293b71fc3af00df8180ab58c184f57cfbfb5d84e6d748144f72a945006dd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:743fb1e2559c47e6275e5d4324919845f5a41fd22f16b7b2815efe533fe88e2a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:873cc39fcc97c0466d7ad771f2513769aae2eea28500fe5fe34b4a7027d4cf48
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:d43c2c642b223edee80f89fa4dd3b03bc0a13e5841eb210f910e25f660ea0d2a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:ec239ffdf661189610b08c0feb30d74c53ac3703674835e64a1f3c011c3b4cee
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:d2c0a9023d68b7500d6af59630b5df7ac0f1878805f7852738a872fd1ff154b1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:6b43ba1bb792b1e4e1b56e043f2fe63a4d4bdbd6a09bdcbbee0bbaf2c7f1a8d9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:0570e01f71746bf94178f735e3173c758e2dd27fcbea6a58b0cb53269f19bc64
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:296d6f45ac14b3e24353e2a76300d7c1497df7075c64fda0633ac1e24c128881