Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (compat)

CIS
linux/amd64
debian 13
Tags:

1.35-compat, 1.35-debian-compat, 1.35-debian13-compat, 1.35.8-compat, 1.35.8-debian-compat, 1.35.8-debian13-compat

Index digest:

sha256:34cffa0f5e99b111377ecfbce67d515adc830435d7cb64d4dabb08141f1b13e0

Manifest digest:

sha256:4c3f3456f90b87f0090ca1a6543bfe05f97d47fccb54a108d1317b6104d32df3

Size

41.07 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.35-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.35-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:8207de7552d4f33bae8e494570225396cb0bd94ab2886d9869a908dcef26fcb1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:a77a0885134eca834a88d1261393c5c077f6964a701cc9fc6608de3fdd4a1448
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:82ae88a2b816241498ae837e563c54f2c5ad9131fc0976155bf98c29ae8147a4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:97b2dc223702d59bec1136435156234efec0261ac0490cd83410aa589b7d50dd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:036d0fb6d21b5c78bb0e26d2f0888c8e19ce7f4eb37e391763e5f34bbdcfb2d4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:267f8e977f2b4dfa8d565da44f382ca8b5deff69007be6a2eb3d4365890e99a6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:4a323cb123dfa59315c56fa5781d1d312e9d1a7bbcdc2161007295b4bb8d69df
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:ac8964d80a8a4417497299c834ac717ffc181c3f42d8acdf91bd09099d22c5b8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:2913774eab79b3eb57f25d1a4354e615baf6fe4736b80137a044a6c7cd059fbc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:f031ca97c125922e0c8c7a439dc9daa9eed3000b7b31294664719517a865e5a6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:6e321b9fd447b59270ed1f6dc9e8fffbbedeb6c936642f5b794c7e37a336b93f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:0b3aad42d14255f0899999ccd865fcee0a8f0c771ca3f2b57c0f36d1330883d8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:4dc2041df4f018e2c005e25ab60fbd644ff31ef6fe8dbacfe36476257d62cae6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:88082da09ee2a1bff8455cb43590842f75b3e479373d2400334f391b00d222fa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:eb808343e9f7bbbf494ef24fb30b6483eafa2d2c5bfdda1d3abcb6edd85c7b71