Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.37.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.37-debian-fips, 1.37-debian13-fips, 1.37-fips, 1.37.1-debian-fips, 1.37.1-debian13-fips, 1.37.1-fips

Index digest:

sha256:773701e36d73194a80691efad30b30ea7ff112691526659dec4c799634ec35d1

Manifest digest:

sha256:af4dd9f86fef28d7b24111bd789a9dc502eb012290c26ce90a837b8032f3b55e

Size

39.03 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:38cd412309beec6859de86e8b272c1c5ba9ec700405b042830f64cf03d482fd1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:58c72cbd7773cd4569b1394e663bfc1bda52e8e17b08f82dfc8369a0ab229359
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:b0225e901f58ff7c84cefa7e11ef922b878e5bf505ad797540e3f3dba3806730
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:660188f31bbd5dc17adc2bb1f73d6265b8da78bb6728a0c84786a26f94842c09
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:259e60672418e0632bc57d11dddb78ac2b9a235e33efe382b683710a0300d573
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:4a301e1d815ddbd0ad5360a6db806425b2c9c18dc79a62ed0b1101e9d22a6e27
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:70d7fa7f2d0c529426e754b161e658f7ffdbb392e0717b159d927873d68da4fa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:25d366d52c1332ec4f25acef1a5eb2576006a3e1b8bffc76aa4527394b6430a8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:6a9524daf00f3d317788b8e07384779e2b6adea09dab80e998e4020d9b8c1191
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:1795aa67f873601adeb65f8989d4663bfaebef5b400ffcb3c5b4c89e7e59c14e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:79656224159b013a0450ee22479f14ddeed94dc15bb3e8a7511b81932c034a96
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:2b8fbc61f579cbabb136c2abfffdc0cf56cd767d353929138007cdb0d4ff9803
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:5a20e51c20e6481c42032ff57d6883680f5bb3d51b01509b4ae49cd6f734227c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:8abdecc276b3030972dddfd6685f24c73b6f2a7d28af59a0fecd10468a0c06f3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:0aa98cf928012e50a701a2530b23189814b3e2aa8bf3213a60320f6b8eba978d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:a455b6e7d9372aee8791d76ebe013771c4226cf1c7f6a79a21618d69624df551
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:14bbf8c2af66a09e8637a8ef88858a74929a81a7243b1bb443006549b1416820