Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 588.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

588-alpine-dev, 588-alpine3.24-dev, 588.0-alpine-dev, 588.0-alpine3.24-dev, 588.0.0-alpine-dev, 588.0.0-alpine3.24-dev

Index digest:

sha256:d13035fe81219b87fedeef7b76b75abea7a404817d97780e5e364d9de91029ba

Manifest digest:

sha256:87eb0b6d39d6e3df54784b2b3f302426ee622f64b020b68631469111890a0f2a

Size

56.88 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:588-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:588-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:9f8e804817e730c0661d1cc1b30ad1d07c3d20f71070a7556c0e40f73f59aa42
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:7b3bee78d3a11d632f465a1fa5f21cb4f73031f4015b4ae390be339fda3fe081
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:7c9c0f072185ed8132dab47d65a2b2777b01ac746f36a8dbf19b928bd69ae487
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:72ed6ad5b3528ab36fe1e1e2d4c8541aa524a1ffedf6c36f866553c294fdbb48
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:f68c3288c34096e4f2a89890176bd5bd6cd100d5657af6319182d81bbf98e52a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:747a6dbee78e5109c034307aea8163c41bdac33d691bf1cb718898e0b9685e19
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:eeb4615c601ca559b0a9c5e6c788f3d8aedc49d9101633cf8622100aee1ca260
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:c97db926a4f50e7556a8a6750903940fade5bef646554d97949a8896fcda6d93
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:17a46b43a8940d21d37b3d8c421ccb5807cc970d2f8d5d76bddb4e3c7108d862
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:5a5ea57e17be0eded0bd834868a43068fa5fe449593c284479de1cf6d1fe2a2d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:c49ae57c112348a275aff13b546503cbc2bd28cbea445273ffd665d72ddaa372
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:526718c877d9f3e90efd7290d739a677d18df5dbf74c88ccbdc61d6bd53e0a34
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:ddb59d1f552f3474cca175152d37f73f3bf099ff221f0d291027fd7c6b883b57
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:5d4146a37c6f3c5819e6834543024274eb9ae5b7b30363eb54733e3586975f38
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:7a1511ad544f02a07c2f82cd09ce4070a60a10ce813dc909855d6db0fca6c71f