Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.36.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.36-debian-fips, 1.36-debian13-fips, 1.36-fips, 1.36.4-debian-fips, 1.36.4-debian13-fips, 1.36.4-fips

Index digest:

sha256:1ead33739442e741e8167cae0d449b327ba7638324f3e8677e1ce6117786c8f6

Manifest digest:

sha256:b9638f0e94a81f9a3c98c434321018c2e36194fc93ffda95e630e2df038ff4ad

Size

38.11 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.36-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.36-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:b4e04b4483cfa0511cbe188d472d6d54c3c216ffd0fa3a1c601be56b05056487
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:b70c78ca45991b92cd59b4725dd150b7ac6e3a3aec5056bf2f196082d2722fb4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kubectl@sha256:ff2f4045868f0e91301023192a2c48b1ef62adcde9ddd9ac007f06cde374d023
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:0f5736cba7bcac307d4eb55e274c3e410e8f2dc277200d303691ded3bad0b751
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kubectl@sha256:8afec776f1ad87bddfc13def292f8cd5ddad69ad1b50be1bf893bb26f4d4d7b6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:67fee937729eb8369e4f17f3e944af11be7af329a4b7089e98850fb88439cddb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:c0f6f887196a123e30d0ecf42631cccc91063d644f5ff2158e13007476c43af9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:996353b85ded3e99f700fd51c05bd56b9b7df8783f5819b07e6af8f885237267
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:27d3cf6faf21f6a62b5383f8fe55defbe465c78ac5919cf07e3a65808c3b9abd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:1f53bf2f1d7e944fef140d726d6d58a3071673e7ddcb6993c79f9cec0759b512
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:f74a21937cd5a10adc1987429f313fd7000297f14810c534103976dfcc4c8771
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:64ac616e86e0e56c66d6f84a48f4fe97c9eb83578527973d81950a6cfa515ffb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:1f7f429b9f646037708f9f2ae8b0e43502c24ef57988e5e26661c003ebb7c18c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:91fe0daa3980188abfb87b2f941c999baf3ecc403319b498228d4efc9eed1244
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:54dd9b8a0ae69de50ea852c337fcd7cb41eb2c0abb3cd68324dd7383433bc686
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:e9cd2c41a0cbf0c79f12d4c10a35971cd0e106cef614cd8fd9a7b3c74f09aff7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:285a0eff4509187f0adabe1f1ffc3d4d93d55eb7b8de60212aa31ecec73bf1f4