Sign inSign up
Kubernetes API Server (kube-apiserver)

dhi.io/kube-apiserver

Kubernetes API Server 1.36.x

CIS
linux/amd64
debian 13
Tags:

1.36, 1.36-debian, 1.36-debian13, 1.36.4, 1.36.4-debian, 1.36.4-debian13, v1.36.4

Index digest:

sha256:8acb194127dd28a59166399cc7858423bfb8ad8c5a90140498a9fc4e37dab218

Manifest digest:

sha256:b8a74ef4172404e1fe2bb523e8f31998d25ff4e2fd58d722bd9834cc87fe3fee

Size

26.32 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kube-apiserver:1.36

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kube-apiserver:1.36 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kube-apiserver@sha256:050179fdf0744f2bc6c45ff063976828977afd6c20ea045bb52eea369abc9c21
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kube-apiserver@sha256:c5117d12fbd33059ada86c056bc9decb12fb029fc9a23f919bd8382f2218c64c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kube-apiserver@sha256:1102c137e5c23b1ddc15848b6330a04745fc28a30ed994ba2dee15857fe29154
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kube-apiserver@sha256:0d1b200704db47bf1dad6da2cb4d97856d3616205efb40139556aa21c60ee23f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kube-apiserver@sha256:9c8d4a51e5ea3229e7d0966c9e050db0ba2152613dfbcefc21bf9ac0d9b23bb5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kube-apiserver@sha256:1f42aff669401920d4da476f39120906779d340daba81a538cbd9bc1a0f271fc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kube-apiserver@sha256:f9552af1c52f74ce340e3eb9d11c2e5c465abd0481bad4d5836a01b4dc67432c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kube-apiserver@sha256:268b8fbdb288061554f18e43d49735e0c6cd9a1120f125d78edf1b2633350ba8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kube-apiserver@sha256:96ae6c0268a308fc3ebba05531a4979291d687cc26820dfa9ad94c82a414cbae
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kube-apiserver@sha256:f8c1b048fd984ef3b1768ee257443b5534a5086bf255f9d69b9a7f3a6f09d8af
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kube-apiserver@sha256:caf1f4d1d5f2a57ed6779d656d6a1393a63f8203c0d5a84dacd51af4212a8cef
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kube-apiserver@sha256:ae06710b7b4a4a15b04fa75300d548643bd207cfb4c458cbcd1ef08b00c0f281
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kube-apiserver@sha256:90b1d6eec5c9fdec6e78c33d19189571aba2980fd8ffa52c122de110cebf1853
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kube-apiserver@sha256:7fe387218f47f2083510d4e0159e65ae6c10bb7a0677daa902d465a397bacb08
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kube-apiserver@sha256:db2a11f070dd76195cd1aa56cefa8754874302357dfc23fdac945abc451f571d