Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.36.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.36-debian-dev, 1.36-debian13-dev, 1.36-dev, 1.36.5-debian-dev, 1.36.5-debian13-dev, 1.36.5-dev

Index digest:

sha256:b8afd8693676cfdfb0a41676664008ba059c675c28cda3841a47d37f1dbc589a

Manifest digest:

sha256:e8fae7d140a357e1a049ba56a7b7ecfb3682c707282b334d424e0d2ed9823c7b

Size

82.59 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.36-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.36-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:f3fdc0bbd4576afcee51cded26751cd93dbebfe64e1cbf68424464ec75609812
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:53c8c0ac29436a5ce1b3e0241495bc5bc721e4b9a7f72644f8f6eecc27d16666
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:07a141ef533c37f17add35ab07aa69d4949cdf857452fd703def692e0b07d2aa
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:9feea7d33b27d213011e14caff7d333bea3d9041247c03494f9b5ec5646e1b77
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:f6b91171c5f36a2ac9486976cb92c19e5cf4e9c734beb0fc4f5188e175834e07
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:deae9d2cfad132545597f026f32f39d80b721e9878e1aed6f37dfcb95fdc8285
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:2b1d61bd9d084bc0e66b2d619c754b85032b5e5d884abf82008d1d1105b7a4ee
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:d44f5826aef60e5b47ae6340fd3e043f1fefaede45a76e3a0a8716e2b1242bf1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:4cb37c34149678d1bcbc60b3f0e301d463c4a2954e4542fd8a2a39df8ddb0a67
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:3f1d16bbd77b9f27d95e811e21c3aee25a01ff92db0888d780923afe8238236d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:312493943932004d21a094c1f5674a8e2078e6e5ad92a56e9481066b872950f8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:342ad0810bcb762474540d6eb64b7cd3e30c651d950b1f265818eacf37433ac8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:33d356dcb9ba1be8cfd5a6ccc2ff1f9f1ba3801e9da123b3199323669269086a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:d8ffa49ec06313dfc10fc4311a48331ae403e16c9e5cf521a3c9c3a4a30ec91d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:2ba553d106b8d236b9dabc283272b57c89e45215de252f2a0860cfa1c6d7d360