Sign inSign up
kubectl

dhi.io/kubectl

kubectl 1.36.x

CIS
linux/amd64
debian 13
Tags:

1.36, 1.36-debian, 1.36-debian13, 1.36.4, 1.36.4-debian, 1.36.4-debian13

Index digest:

sha256:15d1e6b398f07863b742048c31da80efdcae967e3b4edf8cb9eea6ff057e4ba9

Manifest digest:

sha256:657187f5ab433e0aaba44e5318cb5dde76d169b284781d46931f99fbc4d0119b

Size

29.91 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kubectl:1.36

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kubectl:1.36 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kubectl@sha256:ed116d92ac5021724aba62a97071391c9e4425c43d306e74833365337a7c0959
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kubectl@sha256:84b49cbeec140c00f8276972801b8d2a504bd0772d8e4382a2e42feb34e9ddc0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kubectl@sha256:0f31f4471c1464e1d8b9d31a9fd4b3653e02ec3bd69632370f9556863d8ad17d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kubectl@sha256:f927d1f19fc75251d147d7977e69835b389e00a2ba9184f55c9623b10a2f35cc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kubectl@sha256:f5b2b6402724b4cdaf284edf0dc9b2c1be8c7721a2a0793ec4b10d9e813fa904
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kubectl@sha256:4aed73cf294c0e33e04d99f860786f9048dd2d8bbff00dd64accb591decfed7f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kubectl@sha256:b61df062715355cd99c42ff8258eedf15d8de8b0a4203c97af85b5945cdff5d3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kubectl@sha256:93a80a6765a1f3e421ba5d0d7737a8dab7c6e9764defa931c633b9ec03446610
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kubectl@sha256:33f6db700f17ba2a836cf0ee1bba3ba61bbfe745b14b51d64d6280a974cafd14
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kubectl@sha256:fad003c287d8fd0de4a392a7a8d9f251655f602533ca954e64e1c573f5b0fcce
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kubectl@sha256:efd1e454041434c8c0f722bc054ec552122a97025edffeb7f200d2d3c4b8e6f2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kubectl@sha256:5ddb0785b07cc7c7651bd949ff4c858509d728272155473de3c08d855a812c0c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kubectl@sha256:cddfef97e3683d7c9d725f5f9ea4d2a50d86009c78a1bb1e0208e02a4d6aaf91
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kubectl@sha256:94d26283834366c7e91423f31322f61e238ea497c672269e46d38bdecd769957
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kubectl@sha256:4accd050d9731329b62957708b0fbf9f42c480131193493f63c7d4d442de5d97