Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.36.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.36-debian-fips, 1.36-debian13-fips, 1.36-fips, 1.36.4-debian-fips, 1.36.4-debian13-fips, 1.36.4-fips

Index digest:

sha256:3645dc11eaacf9328a2df6cf0924ac8873060b94740284a79b726f80fb26b5c8

Manifest digest:

sha256:3e1bc76fbc23a9557a26f8d24ba10537a0d0cd7e4c827c2d748412d41aa08bb1

Size

38.12 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.36-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.36-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:adadb20dbed227f90f33b9e76f00144c0f8bd7a8725cb5caa00da16f02f7fd59
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:50dcf7f4791319fb91e91f63e71dfed57d87d95bfb732be4434beed9f63acd31
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:f669f6051736dcc9dbd604efc51ab69ab69e8667df6765beea455744b0e6e2e0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:29e4c4befc8d88da0d4472a57bbf3c42dfc5aed7ff86a4a6c0dbdfd2b4515375
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:aebc31e064d7ff2746281c4fc39c765c0c6ab9abc1db0ef0ac44cab82b8a82ea
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:5aa1a9306dc3fb4bb737dee9fa26e69031f4d8477b849d674ffacec8e45d727e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:b0005466dd5954ee18e2c098a72d6c8784a753a65d52b44704cfbc6b82c1f466
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:4daf9d86b8227e8348692ce2e36333ee5af41c4c7c3578d77f725444f46d3ee5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:d9e591b2fa0cdcd929aa86bdadebb8743defb16fcf6ac67a98962fec90d29692
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:7757d2fb24e083841e84f8874247ad9857e3379bcc053cb2ab5bb5dab4dba706
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:85ca300469248939cbac984dc0ed418f2de0e407d24c9d280a2af6c5436b12f0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:2c970dd5d6f3041cf5385cd85883308826d449772f10dee95510b188f1412eff
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:6b77305a87382c99e7002464267924dee85a7956bcd7ae395195c2485b5762b2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:fa115a1525c35fd6025cee197fb8b8a5d91363bbb5bae20fde910e2737218ea5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:1967bb30ed9748464da65f7eb8ba8cc36734597a45de26444d9a1a7a76b6c850
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:6265ff0ca28a87bae500cb819b223212896d52380cd6df11c5a035cb50e294a5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:01425f7ea7dbb4d16306f728644b82a77e88f77485871f4a7aea644dbedf5fa2