Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.36.x (compat)

CIS
linux/amd64
debian 13
Tags:

1.36-compat, 1.36-debian-compat, 1.36-debian13-compat, 1.36.4-compat, 1.36.4-debian-compat, 1.36.4-debian13-compat

Index digest:

sha256:e4f02df46a5bf3c7b751e7410149bded8664ca09a5608c896e955ace248f3542

Manifest digest:

sha256:92394b86e5373db22d5eca54c49c1ce0417ae8c5601e6d6f05c4cf146b8bfc52

Size

41.41 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.36-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.36-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:1b00128464f99d7cbc1473ad6450057b19a36d38efd6a0129fb52e68dd182a38
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:7f5fbcd0fb8a61917c6ee77dfb303244a74897a4fac59e9930a32b8a03b01538
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:5fe2cde772761ac48475c711e35c9decd95b789a5bdddfaa08ca9c5ce4ce81f0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:d929b96a069d657165b4d57262e98064602168a6ca1377e40af647ae13ca7fe0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:4d8105648eb0a70030e40c36d25f53310837cd3915a24ad3dcae040dd7a44dce
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:910a64e9e946cbfd843bf002995a830ee31f744019aaf15643c61e403a9b06ed
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:71102e2f59c4e7b7e583d218a2751bc98042c683a14334447ab80ba1c97dcd2c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:34d47149ef6be01eda290493ad7f29d6c83d509a89ed4854e8aec6ec452b9e32
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:338aa57c09dbeb00b8b3c6c200b98b0f09ca47837771a729226ca47121ea004f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:1079e04661387565348ba3a6759d5a70b8320128d4c3a4b5e8e54d2a753d41de
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:747460a7d821e1d302062b5414ca9776464614fc8ae22fb8da23c788ee3cb726
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:a309fcb891ae0301852abc62169803d106a8603443251989f48336fbe27f3508
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:b1a402dcf657f190d128515549bc617b78b9dc87a4d7c4a361b73d0241597a75
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:bb38924d49c09135aab47737b9d439f2198abaff5cee7f049457007838a83d59
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:d386b6546584bf3e46f0a15f1b3ea9dd726fd17f98463f8acb5d7fc7a65c0987