Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (compat)

CIS
linux/amd64
debian 13
Tags:

1.35-compat, 1.35-debian-compat, 1.35-debian13-compat, 1.35.8-compat, 1.35.8-debian-compat, 1.35.8-debian13-compat

Index digest:

sha256:d4af7daea08f0ca91a3fa8e9fb817e1a77b8815a81464094433883d252ffacbd

Manifest digest:

sha256:3628fbe2d4703312027c0daf7a7f659697e15e35bdca90fa320779d8230075d1

Size

41.07 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.35-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.35-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:9fa8b341cfc36f15abb5da2d6e0cc98928e0ca69b313848386697a5b1e224235
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:dc24d05a656d8834e7514ac2e164d6958b2e962db7aae60d53e2932b6dba244a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:d1a8a4c69c12e71af786d2c0cd50aef85ee3a580b65095713fe80b4cf73d1959
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:d4ddac02b75a9448570bc0c5ed892b4b603aa632324ad3350a20637a989e9c54
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:9d61ac632e5f1b6bbac8dcb222b32bca103a0dc85ced4e93a2c2d800f4574ece
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:9d98d73cf45fa73c6b045574cc7381a0c42d007ddb637c84aa86a3800635757e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:cf29563398ac6c8dcb66898544cfeea47073b5c318512450c4e43b225625efd4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:899ce66d8dfd4241311ca906e466b29e40c2d31e241cb6c0ea94faa29e813e21
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:95b8e90c75430784e807d5a8ff3eca68fbfee1bf07a2d78ec368965b776af809
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:5ae46e8268217b767f7d5f366f295b75ffa67e8bbb27f35676dbbcfb2e105cd6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:4a4d4ecc9451c32427a8b9a0ea4af21ea020a90ffb2ba6bd8647bc01eda8a934
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:edd6172d2366f140baf6c53f92de8ad48339989188977df5b83f0bc65566b076
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:cbc975843e0f06d02612fa3cad7b4da2783b01b3cc5fc301a525965e3c5962d3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:7856588482074c5a758145bc710068170e891ef4b9c2f2e2eefcae7978f355b1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:ab451123558ed7aeccb530f0e5f6037e6c7b713a209d2f095e19e4f5545b2d0b