Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine, 1-alpine3.23, 1.35-alpine, 1.35-alpine3.23, 1.35.8-alpine, 1.35.8-alpine3.23

Index digest:

sha256:1b39de375ff0591b93b3f060ad6bc99b9908f95849122613cefd65f5c47f9c8f

Manifest digest:

sha256:ad1d4c4a016cfe1f8e037049a7f24cd66c0ba0cc56721e13270d72547dbdba16

Size

29.26 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:3683157e9abcb5cddf2dcdd8cb845b3a489b88de2859b4b8b6302fe8a4f665f2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:cd87ded84baeeac94bbc52819ad92755570b8c4401c75d52d4bab749f15cc821
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:99d6c4e801a7a5fbc2d6aee0d02fe25857e817081782431c86c492defab1198e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:370695ad9e37aecb638f442f65429bb8a71f7737758225d5d8dd8a5e379f9879
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:e30a6a0651f48a15d7c416154014ff9b1463240476b78f3cf2d981aa2a55e79c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:2262bfe0c5f3b621aaed570f294d270f557e04e8abddf85543639356d0418f1b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:ec80c31b37286cac34082fb645b409733430b37a396158c9f8271f43eb940a37
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:0e8d3f547f43b0ce412dff586d90295f6b459eace3daa1197b1088e0159ce877
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:a03dd426a3ca8ed4b83210cb039dbf55dcbc4c8524349d4d80c0e8d1cb9b6a37
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:492c721a9fa61b742ab49d9eaa5ac2618e0c82ce8131899085b51f46d0927e78
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:859219445aaf0b271307df49142476c9ab54d78b2f93aaab5faa70e6a90e1fdb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:e173124c2e9666e1b7842faf6c5f120352e4d5cf7e35f33a10171b73cb17a27c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:4a8b070ed65e68d1594be9ab6d8634e2c57372ecb5a90d88081a8b3e9b09b0b6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:c632a088cee9e4b6ab118cf8db91d396a3a9332b77aaedd64872de053ecaa356
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:12b6a3e377f7779fd358334ae149e6cc52a457d74fb84cffc7b60d1cccbb9336