Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.35-debian-fips-dev, 1.35-debian13-fips-dev, 1.35-fips-dev, 1.35.9-debian-fips-dev, 1.35.9-debian13-fips-dev, 1.35.9-fips-dev

Index digest:

sha256:c4d60032fc4c4084372184f39f2ee7278a214cc5be5bdf8dfebcc00daaf4b44d

Manifest digest:

sha256:0bf7120ad37614c014c91c37d820f803b55388f8fec230de87c002277bfb8bcc

Size

82.64 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
13

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.35-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.35-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:3d2cf5f56bfce40b2baf97c7db930af54589bcf9fdeda2f90a083b4e35589eb7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:45b38abdb7a05b67acef12c2132cb9eec92a73467713ff3a8b04bd83e8228f95
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:57c056cac55d7dc7cbbf9b464e7e3e707d269f9820e7c3306f57d9b8fc63aa1b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:898f855c3bb3f00756f0606fa9276c57a2c50e1bf03d3546a849e5f5981fe8e2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:840df3340f40e8ec95e3dd48df1073b562ec7d72e707a1640aee9619f7149720
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:19b442d5b7eb791791ca3f8479a5c61d6fabd0f9855f6b4953e0caec6f28cc58
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:8bb1f1d96251eff61847b3d430887145f7219fed46c7905b945b525c380e6125
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:4ccf9027cf17e6aea0f2d34b31fb1ac489fff6e397633ccf23a0b5a09db4952f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:3e0bf0be071f1ccc2b81234a02eb642bc001b268b3ac9ade06e6e3bcc3a647c3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:e950759d25a63632e8aa5ad6748f4530cdba4aed315eb3e10dd6723aabe43ee1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:f410ec65cf03f88d52e2ae9a38e721025c871c42884634168b1eb2b345a85381
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:260d2b61fde9dbc5b0bf88cad858dbf8e05bb16ae803ad999127da351f3c8e29
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:f3ff866454a463b274a8e708b8a4529239e4765192dc3a4f97eb8ba9970735a6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:7d4031b137b5011529194aae19d520a58c742b640963e90b5a53a879fc2752a8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:c4393318895a7e281cbb42a609e7806b0f8d784360a4e5a8b38056336bdf06bc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:cb76368ea0e444703721df6bf3f74f1bd3560567da6b6ee2cbd39e47d7173174
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:6fa3f757002d38ca094100e5f58524d2fa1224ae2cf3f7fbd06ce7c5e058bb9a