Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine-fips, 1-alpine3.23-fips, 1.35-alpine-fips, 1.35-alpine3.23-fips, 1.35.8-alpine-fips, 1.35.8-alpine3.23-fips

Index digest:

sha256:4796b0b2c2f12e7eaa327e9cae992fdaf199d5dcc4ea5b842694421372536df6

Manifest digest:

sha256:45f0c8b99a4007ae8181d90ea148a869cc4b0076c86c8ec520dd6d9247c5bd02

Size

32.91 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:6a7078534ebe58a29cdf05bb573cd0e3b021c38c0ff604e90f7d408dbe60cc22
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:456400ee73c2c359b27582978b2f18f2657c75aa2f55f1b51e31314c11f46b43
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:91c786b66fb1b55589a61d7611ff088302206c2cc410c28301b7d295b85c181e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:a1f04d8949750f11054cf7218b9580a293b7ce492fc899bde5d8f924d0d5b69e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:b2cb61715955b836615767773f4cacc2709bf89717c86c11625e3ddacadf561d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:ab30feb4ae5991f78ab334838cc2264ff91b5254d382c8186e82010d3b0ae163
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:fee4a0d8c05857f2192460782ffd8af293b392629136e125f81b6a59a3c4ccb1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:43bed84607566064d1eca636fc54bdc417b079912043d58fc2502b2245c21fbc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:9157d5ddac5f03d32b0abe613b2bdf6c1be354518a4d98cebc1337608d7ac3af
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:08f5f88a231254d3563445c9a24438b939d37b87e0656a4248126790c71535cd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:248bc81721e32e8f0f5eb41a2e544c5c754e3e2d29657ce29e77911f6f2797cf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:262d78ec9ce43f87af312a56518f93967f33fbb8996c4e67d1321d3be39c234d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:6cb9174757dfde65ed89cc2e2248cad932d2b8920cfefffc32249baabad74be3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:f306f1bed7fe1c68c90346ee1cfea3c448d481dd1647a674232906661a5a17a7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:904f5afc38ac87604158cbea47d11969b050a663c0e170d62c0a028bdd5a4b23
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:46a26c09cbb62b8831c000eb42aab09e044ed332aa283e31d24db35d0d706df9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:c1070c8b9e602fc3bb30ea69268f2fefaf91bb8c32ca037f2b281f325d61be10