Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.37.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.37, 1.37-debian, 1.37-debian13, 1.37.1, 1.37.1-debian, 1.37.1-debian13

Index digest:

sha256:636ee989c05844b342895a14239dcfa15fdb74f180ec33785b6b13c5c035befc

Manifest digest:

sha256:6028c95f0b0bc495c54d3453db3ee3a76e368ecfdb19dbfef6441b4facc7b050

Size

30.86 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:8273ba50fc842dd934ec1250c8aea1d0e9d087803009831562a5735455ab1a07
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:b645cbe9d645c896dbfe7bf40fa50379620a5f823ba164fd4ffc83f8ba45d175
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:82cc21192f79d20f89063e58847b7862e7ebe9bda517aeaecddccb47df2897bb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:5e99d739e741e8fb278e4b4b391d9c9d3d4c294e151e5cfbbb67d0e230440516
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:2d865d7560a086f13d4b23306e4f56cf3aaed1ea4c77eda8be46eaec72e17b40
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:c8504bccd5f648dd99378f4dd0b7139508107400ad5d014b99c9da86846aa2bf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:1ad090ca00c9b9e401bff2bc56694473a283f1b1439b8ec2e3d7726dbfc2a0b4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:4b5bbd68a8c56b48c458405adc28dd819daacd10359b082e370f2a9da7dcef01
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:3455519ff844be02fa9d5aee3467429b752fb8184b1ba2e172e90d444b34d83e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:e7aa7adbfd661b77690077cfc38b4473b0155dc589959dcda1d7f383da58f8fe
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:e730d7a764ed4ff928ad1f4f33fb3ec7bee5da96189ccf1a2b4b594afca41460
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:5f87c0cd43f6d6a6217162e1d5b34beafd295d625dec762baef32e6cf511a7b9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:9243d2d70618ce80b9a53c0a2704a316a55c9bf6d4db24510373c7e6d009b22b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:90e9e391ea4a9c283996fb6daf5ad415617a6c23908161902462de79a619de06
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:0c90bedea1dd5d78e833afad1fdee9975008fa6b18c570e8bb31eee085918898