Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.35.x

CIS
linux/amd64
debian 13
Tags:

1.35, 1.35-debian, 1.35-debian13, 1.35.8, 1.35.8-debian, 1.35.8-debian13

Index digest:

sha256:f2d415e866ad85a8445747f486f72d6ce02887f1253d6300026d80b60af55dc3

Manifest digest:

sha256:476bee5bb90c2f4f36f813157b34645669d24e5189cf65e587bbe44171d3261d

Size

29.58 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.35

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.35 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:6b70d75f71517d2fe458721d977ca1ddd69836e17a8afb01db2db598bf8a170d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:b6b37a55744323b78716675ac62c45b18d9bd0a5e79339bfd2cc3cfcaa9e25e0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:2cd062a64e0a59668008ba7f662fd0f2c53a875ddb9d0e5b400166113f6caadd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:06092764f1d276e1ab485dbcf9398fa52eb0c08982aaf3175d47b562fcac0022
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:e43dc75a7f0a873f3c07214ffb0d4408fdeff2d3750de612d79fc2085a627175
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:703989a67dde016df321805265110e414edb53c5cf80bee777bc6f27d9660877
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:fc76026176b0da83d9badb91bd67272d7082a9e632e0414489bdc4be468446ab
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:f5a9ae875115116c13f333101dd72e776047b90569cca8999411dbee58219eb6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:96103834caf8d85db30b13c7c83b40d25d1bb7e6ed99db2a1ec4f6175b9eae4f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:a260a457cd37638a02be800f8014598491d5b96960ea25b769d679e8911f33ae
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:28054352f47e880eac447cccf07ada5ccab7a419e09ac38c232b6db0a8d4b8d8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:145e8d5926bf8b514bf001cdee6eb9128db3616cd5d96a0bd9e7e11f85ebd837
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:6c91ab58cb5bebce4bc27301c15db518292b1fb58990a6b962d618622deaca24
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:4441e15502392ba30ed30fdffdd458c1b67af23a83659a3c7119116959d47745
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:b28144b63d4ab8927139695dc218efbf9882578933d41253a265c3234ec72390