Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.35-debian-fips, 1.35-debian13-fips, 1.35-fips, 1.35.8-debian-fips, 1.35.8-debian13-fips, 1.35.8-fips

Index digest:

sha256:bfd2677354a2427c0106b144275b5c4372c8d67c6cbe3ac16f2b079c6fb39962

Manifest digest:

sha256:9aee6118043b0871f3a876a5445a14634e49de1a7560f00452ab8497589c1de4

Size

37.76 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.35-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.35-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:4c8e49c5f9dc7460a67ea72d64bb2cc6ef48aadf0e4c230cdc315f63a0135fb0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:cf0ce112b924eda084f4468baf46a02a21f842fbcb221edde28cc7fcf905b4bb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:283254d33e3ee77008b7b2b5110646cb52f7e0994e49845e6f3e4279804a5f23
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:8245cf50bed0a662fcd0172349e9eeb24dc74d5f76057d8cdf9d41044065c422
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:ca64b2ae6d33b9698e5681d8631f9659beca5797c769e4ade67bb3ddbeaa745a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:bf81a3f8ba54097d4d85369b9dcb8272426f780b0bc3b2985f13a2b47ba20af7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:bcc1f6c4bf60fd95333c8eb8cb18ddd59bb2ae5c476380f83273d3effdf43d66
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:335dcd828cbc3a39c2d317a87c5c404c77c2328ff15805347a58ff092ad1c982
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:a2c85fa185be21cde5a5ea29092b46a9816ec611442796f26af9c399fcf24538
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:afe82291160a878713516d45d9408fe03cc036303e237538b806722212604c42
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:af69bda00b2f4978380583f02824695ebe0262b77e1b44534cfaa075f5614a73
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:5d0334a6319b2b93265c0a8111640180dd3833af8e1b066b2dd72ed78dfd864f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:0b3908099c45c0cc8e50e5349fb71029d02831f55ebfd7d26bad690924cbd544
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:c891693ebf39ee52ad3839e73b4850279c0ecb282777d0dfe638b396c1f3e650
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:cd0a6ec5f75ae58c9c11954e2b0a8751df4495116cacf68a6b229884d8f7abf2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:473dbaa46eb6d867e8bc7e2ea6665bb198f13e88068ac82cc6cc15370800797c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:395b7bc688a8e3a6469c70f7bd6b9a62593b8ce8f5e1b879731eea2bade7c548