Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (compat)

CIS
linux/amd64
debian 13
Tags:

1.35-compat, 1.35-debian-compat, 1.35-debian13-compat, 1.35.8-compat, 1.35.8-debian-compat, 1.35.8-debian13-compat

Index digest:

sha256:62f0670d30758851683b09d5c201fc7b31e8a15784afcd2a1eb3dff6440cc735

Manifest digest:

sha256:c27124bdaefd799389a23c7e6eebccf4d018e90b37c5911254736dd96eb1f76f

Size

41.07 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.35-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.35-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:52887585a83d42e7704914c20b786a58d7d7dd5f7b00619deb0cca8abb2f8452
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:50e7ed3dd933aad25b21b63fe3ac9dd073a542d4f42c220e31cc0a0da02dbc86
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:9564578fcc1714be78c6cec77f49f793c3f43773597a5ff8480a04719581db64
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:39c68602f2e45b9340ab1153bb27c799ab642a6b5a1ae88d531f0dc1b30d5c2e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:4496cb40446befd218b687d1fdbda4f00e73cc29e12039fdfd0ce18fb4961dd1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:a30dd0a9d24139e104c4c27c0d8a4f7ddca5a732359b50bc7d10cbccdbc05b06
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:de3fcf4d862ae028daa8eb49589f8115031d3ded20ecd512ee0544134c416043
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:a92e4a78403334732964c9d46d1f7fb93cca58f4b6bc4979c68b311eb2088be5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:307cdb63abb3f0633ae2dada7048eb5fa972f475a082094effb1a9a391f7f798
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:43e0631316ac8dd410bbab9cf0c2962246b22ae94ec647a77fe4e10f3711cb1a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:7b18a11b6c3b0d7d704e96bf32580aa39a4d21329ee184eae033ea9440f92499
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:de641f9321d28f6ec467b78ac1d4091fb221f223e2102dfd39b916ae460b34d7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:1259dfc295d256d7a858c780fb793f4c640c9fe39b681277a5b436ca5f9fff8b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:4afa0a5680c93435c43d1cb52ecf27f47fe0a55ebe7ef61803ba4277dfdfb09d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:969c65185b1343fba0f0e8c289c3b2990ec9a78bc5751cf484b1324e7158e462