Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.36.x

CIS
linux/amd64
debian 13
Tags:

1.36, 1.36-debian, 1.36-debian13, 1.36.4, 1.36.4-debian, 1.36.4-debian13

Index digest:

sha256:df8c9d07d74a04af2620ed1550f1ab4fcc6b0aa10018ee2c90bb4eaee827ef4f

Manifest digest:

sha256:582490002923df8994194e23ccf6a01612fc1f602d27d54046f1bbff1c8d1c15

Size

29.91 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.36

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.36 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:2f6dd3a4d672430fff87485353d188623a3d1583b85a255569f24d025e585bcb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:a81df5ffdbb4b57c79dfd822977d2fc631ff13120012c858b118572554465e36
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:69e5be80826998e15096d15c3519fe362e9ebca726b8671c936e647a881a8e02
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:123778807418406c856ee7b196c44d09393480f04d25de3c4e61fb917e4ce392
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:62d042488a7475cece516c8b7ed4ead931f86f5dbd162ebf7d2c0b46db69e659
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:1333e6cd2767b7811d72322bfa4d3644723f710306ba296df44c454bcbe68bd8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:b9f24557c611cbc948924c598f099a5a1f7634d7ff50f96ecb7b9cd900dc5512
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:6d0bbfad400669afee946bc9ec2c40325d9508696f92966453071398afeb77bb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:82e51ad6e5db3d83214f6788b80e7a865534743c1cf389280249e4c837742283
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:d054885e7d4150458b620ee6f998b066701594dca5145b43b1594ac22b3bbba2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:4bcc01d18a333437701a7cb349d9fd9298ce37e5e9c26f677894f55be415b36e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:5835b2a82d5bdfec00684edbd80cf4a963e3c15c1bfad82f4405f8a299e8962a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:33114f32b9174e9b8032ff98047681e346a4ddd9afb0a110d7c413f85784b2d3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:973355099f97b484d371caee6fced330f62b5ec0d0c717ac82373f6a4bb97747
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:8ee7415c22fb7eb106de288ea5647664aa7f03a83439c46800732f1be2f4f2ea