Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 587.x

CIS
linux/amd64
alpine 3.24
Tags:

587-alpine, 587-alpine3.24, 587.0-alpine, 587.0-alpine3.24, 587.0.0-alpine, 587.0.0-alpine3.24

Index digest:

sha256:ec3fcb1b12e2ed0a778bfc9d7f359af04c8dd126cd2792e033bc8453cd9ccd73

Manifest digest:

sha256:84c52117b5cddbc2d13a3d01731a1a15e4e64f9eec4e7d7bdda4829089776071

Size

56.57 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:587-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:587-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:70a07092f431052ac5f3bf923795a1607b3b4a731b86c63f3dea44f963cf1c73
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:db4d7e6db8eea7a67da1c89ba992b6629453fdae9c200d3d01a8c564d57e8c70
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:f8cd4e175622743e3a3cc58ba263ce60428624d08076fdd61ade8b1e639ff0df
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:3c997606d39592a836bbfceb20b0002daf2cc24abb3468470eb0a9b33ee68c44
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:cc637d093bc3580ab98428387f87196f1ef048cd71fb64fe758d116449813fa4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:4c276001ecc047ef400cc75cb3bcbeb685019f7f7b1eb31a15c6cfe345cdba32
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:ae73692b346e7102c2acea868892263f93d61939534aca4e425937b40867ba05
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:93f864b75bb166eb1e74ef3227f6d231c388e4f636e1c01730020b16a63ba4b6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:df93af95c534f8591ba0df58ef8a53a397f3f4c5ca7eb0ff575f9bfa0d387347
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:2ddc82f46850402de7b25fd7c43920bbcf379703e25836c447d5703f7e00b887
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:22a26fdfb190d621d6c2b967f721e9235cdc5953159ebccf06a1f7b74f3c2b6c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:9976db628d81af8aabae03881fc092438f41a02afed6ade27d2f9f1ac9655952
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:f495cbdb4cede77f9257da6446e3e678e33be41ae6a95162bd6d8cadbca7afd9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:cf3dd27a7e4892997c2ad8975407e1da4e9a094388fae3c20c92fee1f0f8c1b6