Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (compat)

CIS
linux/amd64
debian 13
Tags:

1.35-compat, 1.35-debian-compat, 1.35-debian13-compat, 1.35.9-compat, 1.35.9-debian-compat, 1.35.9-debian13-compat

Index digest:

sha256:462ba8989d5294b290049f6a9bb4a7460a2f5185da5faa9bfce9f5d36bdd5f59

Manifest digest:

sha256:e6f73fdd561537f0aae348115cda63dae9e5a72533528bbdd71ee5810c311baa

Size

41.10 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.35-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.35-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:a6d0e04a9a7b61aa21c04a5a9182b10227d512657673044b4ea5d54d6391432c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:3ec6d8233e107b53c42e6d3422b3ac1ba2b6a9a9ce344de3b184e27dd600de69
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:815fcda93cd5b96c529093c42f59c778d2be82f19086173ff4dd5153ec1d3eb0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:54447ecc9ec5112a2a2558e2ab953b1bf48776f94b7e71b42a52a2825e8b805e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:4f7b0985ea5fa4447a681c824475c7cf887aa659d55b438e6045df9d1d1c4813
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:1efe2083e0987410d9eb2bb6738c8858e8377f6546d5d2566c7261a4d91b0419
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:fcf680e29f4ebf69103403f6801bfc3e0a41afa0645b18c17ea2044e6aff1e46
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:28894340f752396722e84b3fb6a3005c159afd9dd23bbf0a88409a309a164d67
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:9bab929addb21e2bb8429545c4bd9ac95f0a656d1b61f70c278f8acc1a4b3536
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:4162fc2d6db6fe51baaa2669883c0b6b0f8efd61719ec53906a9d827143fd690
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:9e7cd499700efd33418bb6f761a393162111c6097089d2efebbcec41f36399a4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:0a96167a372f77ee8e6f51d03d8eab6b3a95dd7a9d5035d6d8ceff44ad9d2f09
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:31deac090f6617b72e8b87bffcbba6a2806b7a55c3ef850abcf32d6d6166b335
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:f938a9943ac457b1d34927d62a141910ee300690f3589b8b9748f4961173c0b9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:d21cf326e2ed6159d465eddc56387652e7b336588d5f66b877bc7b6ec700d4bf