Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.36.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.36-debian-fips, 1.36-debian13-fips, 1.36-fips, 1.36.4-debian-fips, 1.36.4-debian13-fips, 1.36.4-fips

Index digest:

sha256:9ff3dd7dc48005101b2b5c6e3a12ed6e2dfab01f1f433a6394ac57dd1db3caa5

Manifest digest:

sha256:1bcd418b96b0954b7670bbb473db2dd5e006f0d1b4efee7d44116713e5c98de2

Size

38.12 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.36-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.36-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:5ca949d16e97b5d0927c22b8787a6bebd0250fe9ecab068c3f42374e19b8c6a1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:dd763a72c5ecf01b6559d5ad68cb92b260288a1789fbf44cd540cffc29e4ff09
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:e426c63764ad6bb24edd1ceeb6788575bfdff67ea0a17634fe249df302432927
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:dcc2e56b9bf1c9abcb689d03b9c60f67d241329d407469fdf8e1040f95393c68
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:8dca3bf0793087e10c5970d24793f62c76b26abb9e68e112e8d38b2928af22bd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:67586b8c5289452c2833948b2c0bd0a1e58b5c9167aec7546093869a27b17185
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:74d2dde51d62f849e84a9a1bd015084228be7748138129d68786fb8c79407942
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:1e823de5eb3ec03eb87f867108e01437f5c867314c4443b8b986243427274b0e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:5b66ac3228bb4afa7c9ab9e7e1692a0e451f34bb938ad3845e81bd9255f8caa3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:a7cbcda2b88881bf60071836f2cdedb7d5973ea35185cf7e97091db10df57994
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:fbdf7b0ad0b2cad02bdf52a405db66ab6b621aa333ab840663f3fbe8aa280edf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:ef99c75319a7dca1c8e1d9d1176c8c672d7211e1f2bcce38aea139033462ade4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:413aa009fabec5b9073431658bac5cf2a2699c33893601a2f9401190b7c0abbc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:e9b0e354b7f2a705e97161d6a547f6dae760dc848a79577397a4b74ffab8b269
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:139ef217fad0e645d4cae21417348704998a5250d94430e6ab5e3cfacee2e12b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:714c2497591607f00c1854f83733cb8a5209ca18d9369a1921fdf2907f1695ba
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:0c9d5ca026780dcd86da52fffb9172ec743b9afc6fa0198ba834c87fc898cc3f