Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.36.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.36-debian-fips-dev, 1.36-debian13-fips-dev, 1.36-fips-dev, 1.36.5-debian-fips-dev, 1.36.5-debian13-fips-dev, 1.36.5-fips-dev

Index digest:

sha256:5c3654343f3e78825abeb9dfb1aa0b72e6b5030f18080a82490b362431baeb58

Manifest digest:

sha256:8a1845c239632ff11bc1a779f44bda2a4a09027d19558ce026340687c74c951e

Size

83.38 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.36-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.36-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:3745acd1260804d12c5a577087d819e9db607e90dca99281c910a4d03f77caf2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:15b1cc8ee695c9e8f8671c6400ca1ae0cd9950786f51c2d14812779f128a07e9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:ec7b7c3bf968b4484b9a215594f5f282152634c16ba6a422ded539b41ff9e9ad
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:61f253f131cae9c72e93cd815ef4b62096c11398408a17ea57fb59fc318e76d6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:40b502a40f76fff029b9e448b187a12fcbc76b0b5a4f97f91696b9601ec13dd3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:0f890ce17a0fff2ca2a207b4cb33ccb13f9e055028abc3105cfc3a6a3b7c4f77
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:c8cf089d58fd848c992b509d79e0bb00c84194dc930b6235252689c2544dcd8c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:c440c60fae2b17b26b4035e5098a27eea0acf04de660514283d222072f54774b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:89a8aa88d6ede35b78962c11bc62573502cbcd724bbe143d46535a265d84cc14
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:94a23affaa5087d9dd2933df42482ef5bc473bd3431249cec10f580312b99e0f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:5a8202c8e215a124cf1c56030b41fab675b5ab909152921c9f0d2c7b40361e35
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:38e13b0b140f304a8b8a8fe3b7eeeca1f6c7332d04014af585735f01988f0164
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:3d0b365fb68c7afc49533fb86f8f85be7de56aabe95df6f06919c96de37997db
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:f65f74b8a5521ee7a0b6f5ed8b1d0f8c99d53c98a15ab016711cc4ed5d5456a1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:cb3fe73ebada0e8aa7df67a4da7c6d76eba92c705c2024afe5313d9319ffc7b9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:4f115cebc7acf3cdad6cd73da039df401058c0936fc9644e669bea896233b661
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:59fccfb9a25e5030415a8de5f7460fedfd59b862a6bf82c92c0ea9914e6dee15