Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (compat)

CIS
linux/amd64
debian 13
Tags:

1.35-compat, 1.35-debian-compat, 1.35-debian13-compat, 1.35.9-compat, 1.35.9-debian-compat, 1.35.9-debian13-compat

Index digest:

sha256:f13ba6a239ff079f27b6d0c1897433a37c49b4f4062313b7fbf1daf01b22ca25

Manifest digest:

sha256:d5ef966947831f80bad609d76edd27c4dcd4e5e651e99fe86694c540a3d8871a

Size

41.10 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.35-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.35-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:284137ac8f732a0c7c70fc7c35562c5d8c1b626eab07499b66747b921efcda68
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:b0b6c57ea6357632428c48812e047c14b0e78e3e832af2dca6347d108095e3f2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:919548c36618ff249d94baa7d87174b4beba6c1ef9dedce749918905ad6e9f56
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:b7bfc7ffc400835da785a61a906f5f3ef6625a9461b4e40585a8ec06ed8ea40e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:c35fef00b24cde9d93a2806ad888483234df6bf596eb566ca264dd1a73312881
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:66b3831a3671d39ccf7282f9569d02026547c074d68956055ea36077b012f552
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:1e84aff72541bb712ad6fa196935e4867bf46002a460988127ba9f3649da4d67
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:2bc2ff7ecc78cd791f1974f6a93520a14ea3019e1e4731c70acc9e17a4c6c566
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:b00d08adb3b2c316bd415a13d1c9083aae7c5450b337c0e8ba5e294acf3a6630
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:3578919e32a9bc5ade43f5f1e63aef52cc27ec92edc701802ed76479c457a61a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:f0551664aa7d39384a9bdf7f4ac05a5fcacf23bf5a9009a58b3b5244a47f2477
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:89f501332c0cb9968180c80fc412f6aaa1de37cc8ce35c0288afd6d63ed01815
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:0233250dd69dbdcb26e8d5e36e10810bed7167be915401396093699af778843c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:feaef32b3d8ae11b6dbc920719cd568352706ce22e8ba0ec836b3821eca3ff44
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:9d67ba9c2136fa29c64528e2bfeeebdeaf276d09bd1c9a89f251230b4fb38d6e