Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 586.x (emulators, dev)

CIS
linux/amd64
debian 13
Tags:

586-debian-emulators-dev, 586-debian13-emulators-dev, 586-emulators-dev, 586.0-debian-emulators-dev, 586.0-debian13-emulators-dev, 586.0-emulators-dev, 586.0.0-debian-emulators-dev, 586.0.0-debian13-emulators-dev, 586.0.0-emulators-dev

Index digest:

sha256:8ce49767ad29bc8f574bdec1860af42a96f013da4767eac48e186ce0b3e4f4be

Manifest digest:

sha256:fe4d48f5bc44a36f4b17a7b5c3b80a720eb95d4f02098691df137ce93541a997

Size

327.31 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
1
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:586-debian-emulators-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:586-debian-emulators-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:0e2b9eb4bac577c4705bf2f2f67f5e74391d607b286b3c11e02c384ce37097ae
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:a17fa83732c4835f38a0ab2b8a69d5cdcd2a206fcc1fea7e17c6be2b80cb55ee
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:0f1c78e61844ec559832f3a2c0d96180a106986030b684f5f418f5e7479f2e3d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:0025bfc8523146c2872e92f60606cc2479d4c35cf3e17fa7cb897202542e53ee
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:8c6a8fe4c8a5c04959cc0d4e1ea3b29b935c09f2ee04ccce44c98c30542d1b24
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:984be70b7acb03b4c0f540e5c261b2dc352e8415d4a5c36c3daf52acf5af7836
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:d40df4750ba86048bf9a59e418b8974b7874b6297d3c9bb9f45eb6cb491ac21c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:e74a69453fe4ce9b195904711e1668f5f43d7d5b00bab7d2295f369313cafb90
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:bc86531e339668d7fc6b640de9fc11cce2dfe8c90f3ec5f9c66f6082ee5d9dd0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:f8b6fff9e7f6397720abf3669de48bdeb707943e450e120aca0f58249b66a0e3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:ca1c6a09afdbbb93fbb99ae34d007992e46dfa31e0c2d425a2946ac12266d584
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:a5f99467a4d8d802c2e31045a896f2b870904b0258643cea3fc464dcbccca0c5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:0afd92d01ab89c59c9ac5bdb0529975c6ba81de922bcd8b5c24e69174a9c6b10
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:3997f5f6be7ca39a97ee7ba3330165bb035d14cb2ad36e8410686fd65a6db8e0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:053cd06d11cef142a887e8acb780b7ef55f2ea5774c6a671498ad4a480715b0c