Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 588.x (emulators, dev)

CIS
linux/amd64
debian 13
Tags:

588-debian-emulators-dev, 588-debian13-emulators-dev, 588-emulators-dev, 588.0-debian-emulators-dev, 588.0-debian13-emulators-dev, 588.0-emulators-dev, 588.0.0-debian-emulators-dev, 588.0.0-debian13-emulators-dev, 588.0.0-emulators-dev

Index digest:

sha256:7054bb0aac0b28b2cba8ceffa4de621617cdc4f19933a8ceaa8311846dd5da14

Manifest digest:

sha256:652266e847ac291e7c23a51dd4210abe23ebc036c2c11b1001631620912baee4

Size

327.71 MB

Last pushed

10 hours ago

Vulnerabilities

4
17
3
12
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:588-debian-emulators-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:588-debian-emulators-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:e06d15c70451c01804b0b8b849630f85e6ef0b1b7522fe0fe8bb9e08ec435a28
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:bb130bdbbfe6d40643d3106f90c08c0a69576ba25463da8521128a2d4b378139
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:7b7cb79651975b0097a356066ebc7bb9a4ba9e5084af4894372656d768232f33
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:eb72b56f08ecf06b347fc4dd2ccbe08e8109fb6f8cf5dea2bb2a2a4079365cdb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:8483d20bbe192282d1b0c3802c61777b8d840073a5009b39a7e9f4a1feef01a6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:09833540defbd5c05971f1d9a52693f308dad0ad7b146601501c5e11452f0ea6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:31a27bc24e787e66fb1ac910764590c596ff45a8fdde048df19232964be15977
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:7b908b423659f3140494960079ec091935fe9790c2852f2e92078003c7372e7b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:01260f01618e1f3d97dd6b1be029a0f6ec5ca12eac3a58a8cbc5b9bc9860dbfc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:20c9b15810bc0960e75fd31e07fd8fada931d78e04ce6de67c43490a9f0d5c92
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:e9f7c8caeaf8c190abfc342776cc9693c9b77c2454548f7fc705472d07499d9e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:181a0a1865b39429c38b909a8823c42b6d48a4103a4051f640bc52387fce931d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:9ac8f17f00c37d120db7af646f4d13357a2ab0afae21c28252ffb44da0dfc321
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:393f33b3b80dcd4ef6ee4a8e651509a9c88623d00f0c8138c4796cf3f6cc2d32
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:a14064b5302bc0debef2aa3b347954a93e1bea4cd737f94365d6745796c4982c