Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 587.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

587-alpine-dev, 587-alpine3.24-dev, 587.0-alpine-dev, 587.0-alpine3.24-dev, 587.0.0-alpine-dev, 587.0.0-alpine3.24-dev

Index digest:

sha256:dc4965849086c148dc51a9df186cd0f06ada5890ca576a5b1d3ad62b368e387d

Manifest digest:

sha256:394e6cbf4313fd63422f918d708b4ab56b797887d3a68ff836512ac7286faa0d

Size

56.87 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:587-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:587-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:5774efc609bea9c22c0c43279b47f56ddda03306c53ed13b8aa097d3193e9d76
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:c5f9c1ecd103fa8d6c39a7c9aa3b15fcfd0a1306f3a89c4398d401b9fa17a791
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:d179118eed43adef7fdfc6c8a8bafcaac445ac1e10509dc9e66840a1badf0ff1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:dfbf46da60154718d39a87d5d612176b19bd3c4891e71f8f60071617319943f2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:71dc336c531037e8a9f4e5b59e4ea185d11bc60f941de5f10a3325cca4a69b41
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:6f076bcccd2bababc80f16a646f332527bd4ef9d1d412755ba0862e05026e967
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:99b7459547d11a5b6b950e7d2b231adb97ae53b3a74200c9bba41910f2c24552
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:7189022f72eef5560ad0ac46f3a383a8f36808c65606bdabb9db6e70515d10bb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:1dc37111a8c659592115c2100bdf6c868ac764cfaac74a33234c27650349604c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:c8a89be1ec72e400e6f607cc7955901c7996016b85259f8408204add8fb0729e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:86fc716fddbeea3afdffbffbffd52b2aeb6bf7158a3cdc59115b880043925119
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:79991d5ef05a78a62c43d96781843b5b53bca898c2ca0830b5b527c01a364914
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:69635945d70f81fa8bae56cbb85e3152d1e4d63abdfed2db87b46edd4b919cb1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:6ec10fcf78d212fca241c895f5e7787c37ee0debc1a1afafcd1472a8abae6ef3