Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.35-debian-fips, 1.35-debian13-fips, 1.35-fips, 1.35.8-debian-fips, 1.35.8-debian13-fips, 1.35.8-fips

Index digest:

sha256:88a1d10b98abeacf80836ba52184c8950ef3dad0748e724bf1bca1e746e4f1bf

Manifest digest:

sha256:8eac641e2ed7097292bbe3154c5bfd0da91035118be85251a2e20a24feb042f2

Size

37.79 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.35-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.35-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:90bbcb897e09498c1040c8cb38e697d80ce7bb5d73888667ab583b261b6d3e93
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:5c93f55e248a142ff09c0f6923d7ee06d350c82a413e9c065daff9de2fd52c47
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:ebf6c23983293b1266452e85f5231e1a191107acb421022f30cdf80f9e2252a0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:162a74b6bc0427e3e3f8f77895e8bf86a1d149cfa7cd55967e2c42cd7db81fe5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:df8404a47c183a9d04c5a548daba14f8a618185636b6be0efe9f2a14d2664db5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:7bce3e66d836da342076084a41c4cc79dd925aa6ff4c939800a54f7a8630b37e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:2714796f0e0bd1c7aa5264708a5754ed9ae320d6c901cd282561525ada13f148
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:ad92c704628e25d12a31c0461e4327d873265b65deb79a2138e3e965b0f4d75e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:02505b6ac1c191fb4e614ce97d2bd8d030b5910d83e2f6c9fc6eb589ab8918cf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:277d173fd405f1087527ec4d98053ec5adaf5e646054345853ee80a8e67bb99e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:c28ebe8c9bb46e84af620cc52248d8847fbc97489261ce71c8a4e3a31fc8f807
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:0380342f03049f5d8f50a41ae4ec7c5a3f8b5b2f6994130a6c6bde88835c96b4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:08cd9a031f81d688db8fb4698c4f465f7bb136518578baa0f1712a086f819759
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:57c080dfa016b8c9667a4378df25ed34f664872546efe1f7e53bb2b93ea5e22e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:64d30738b63d726707ae1e3199da05851415941a3b2451da262f4210d01e1b08
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:75c2eb5b18a03b4590aae2aa92bd164b55939c6234b3047b0bbe0264a27117f5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:f2de5ad7f037a36c41897a8ef45ccfef3eba1e5c468f8ec563cef06eeb32fd69