Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.37.x (compat)

CIS
linux/amd64
debian 13
Tags:

1-compat, 1-debian-compat, 1-debian13-compat, 1.37-compat, 1.37-debian-compat, 1.37-debian13-compat, 1.37.1-compat, 1.37.1-debian-compat, 1.37.1-debian13-compat

Index digest:

sha256:a7f646ab57d0c40fa764e5da83d206d48995940dfba77a70f8d41c783185a48a

Manifest digest:

sha256:b1ff0de025af7c4a066de5f408693e97692841663258037ae0989fb511d4db19

Size

42.34 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:d46503c63c84648563be5089d5f8001701ac00ee0562bdb48b1291610bccb042
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:58dde2ce0bb18ccd779987cbfb331f14d73dcafc5d16666472f9864b84aecee1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:944bf605be8f9fdf2b4225c5107be4b57f221cf74d980f4ee68b201ae431ba13
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:f6e45fe063bb58e7607b22812bcf6311635979209e7a35bb434c0943e7aa40f1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:962c20fb0ac41b61bae3220c613408b3a1f8b9499946162876bbbc0014e075d8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:f6e2000c656cefc0749d4539df1ed4b06f1da9b334bfd8f4ba6e4dd5edf62002
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:5ec93d1dc69fc5f2879d7088086ea4e03446248c6107c33b8bc5277d4bbc014b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:fb31a0ea07d2ea1a665f4ca1ea26e884061faba75b7f78fe710afbf9e0b727fe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:49bb403309ef68fc6f29ba030a6ac3502087e74503ad2cd279bf8912c83fcc1e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:4d7b44591511157f34a396f159a57285ffc20f1aff3d5ad9e1a7d1e8ac0acf81
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:336022db7beefa86d576cd4798be95c45bf54a48be57cef68d86bbaa93429cce
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:28bad4a1bd098d07ef4ea63319d04572e87c3352808571dc3573891782147668
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:ef2b7b544d425918b375a5a0f0433fffa700241522ff8e2dbe089f72a3242212
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:8baeeee5f1b60a4cf97891aa0d6dbf1287d7d254493020a3c2ab79cfdd188dac
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:5cab5eb189efd0694b8e1484da1d450b890e1d0b6b8ba4164689ce431b2d2d52