Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine-fips-dev, 1-alpine3.23-fips-dev, 1.35-alpine-fips-dev, 1.35-alpine3.23-fips-dev, 1.35.8-alpine-fips-dev, 1.35.8-alpine3.23-fips-dev

Index digest:

sha256:ebc8384bbf5a719f5449075788233e87824228c4d640fd21d075db6de16d4886

Manifest digest:

sha256:92398ece5a0dda32db24cbd5fc3b6ba8ee28dac4226bd17ee1d66fc5ed9b6e8f

Size

64.69 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:f173a09390172ec9d3166f5b6f185a59cba3ece31c0a1d0246838030c3acb7cf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:a2d5e2fdf2b7676bc9bd84e88d34d699565b74698b599e8ead0f8305ac7ca95b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:1c8b21b51381f22a8d54714ea302ddcaa7fc62c31c2e339f87c67cc172259b6d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:135ed6aa8401e05989f1fa520d059ad72980d31ee342c13aab0e69b3c184cba5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:9f76c6879a8e665f231ca93db5ebbc6e95ffef73619b0d871e6d3106675ecee6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:b1cb9175c0548ae80599c064a52c1d6d0fd73870583064c6396d7afc689a6cf2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:9789f15a550cf1e979d3c0d478037da7e17fc1dcbe7a59ec74acbada457b2b0b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:60f17ac0cbc741ebe88f08f05a6943ea2e8b5c2e2e132f68a0d2badefb8fd017
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:55d9d54c19638d25e0d1c8ff998099b6133ecadbba2e8a8c3600e6b971fbb9d8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:caf33f11f9b2b8dc0d84678560259c3a26a444f84907acfa94095bc56c142e2c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:22f6b385f96ff381a872b6706bf2d5e9c6440328b5229769188c479b0e67ea70
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:996fe56e123bfb93a0f5429fdb524cd8765e7cbf6940dd6c79035a4fcecec710
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:b34c0e241373f84e03f1d669d279915cac5b7cb5b4d7d24d16190ffe9c9b37a2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:717302d96cfb9d116e96c100c8d5ddac6958d46db8ec16cfe2b04d0b63536c0d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:722817195a5fa999c7df1703a869ff45056895755b257796bf44d52b392cb89c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:f423335996d75f825374e67e1c3247205a1feeb457003947ec4ebeeb4fca403c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:74dff16b0b89c81d6647442a2b8c659c512b2d926f0f9baa53e731980a282076