Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.36.x (compat)

CIS
linux/amd64
debian 13
Tags:

1.36-compat, 1.36-debian-compat, 1.36-debian13-compat, 1.36.4-compat, 1.36.4-debian-compat, 1.36.4-debian13-compat

Index digest:

sha256:8b2ca5603a1b77e87aecd13a86ee309c8db8e14412e1943d68d39249ce9b1c1c

Manifest digest:

sha256:634e8e0649a6b626c59da730c98ad55d1effbf522e14c99c8bb6c3f6b558d216

Size

41.41 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.36-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.36-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:db9ec876bdf0a6a24696c6f958b7f505d1d3e590fda65413143074648cc05477
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:70671cb8b543643e1876623abff994cfe711da3843f79c17d8bccfcbc9932f3c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:02d24f576e7dd0127275145e6c88daeca15b405a576c6ef19dbd9c9d238f5f1c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:2d9e80ca9c1b621b30c58b7feadbcabe99a89ef3b8096fa8d1db1ee3253e5c8e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:e8bff9c7105f0d60cb22ea2dc9a62094c9ab71bec3b0a29cf5a6fb9626fe9775
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:99b40eb34963b1b35083dcba4e80f1314c9ad3f14c9792512dda60d629a56fc5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:28d64dff01c12f18b44e14b5ae58a6dc0b430675f2bfdfa44a38062bda492070
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:9583b62d1c8dc51d84c2950434d68c3e0bb835b8acac3c3f2829fe3ca4fc8fa5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:a9755a349e17c872aa7ea511d5e74a88a3edfebfc3e28ecb71eb14763c9baca2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:46e03afc03c1a7914de5730a22d460a77521c92400efb79319bd356278ec335a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:cd42a5e52b7369314276cad751fc6edde2b399a49f1712ab7c6268a07a0f13c4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:7fdb94fda2bc3241ba1ead99ab1e1b3ea29d4d52a98aa20862f551421561dd25
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:313ea0942170fb301e0657b999ee6ae5589427ba9701829f170c0bb0907339f4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:b3cf85c0e76ed87e046163dcc481c465e90a6feac9f00ef48cd8625b8f411396
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:0ac9b40c98585d4df4d255fbf717f74035b6a4e444712b71a1b40617b610a5ed