Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 587.x (emulators)

CIS
linux/amd64
debian 13
Tags:

587-debian-emulators, 587-debian13-emulators, 587-emulators, 587.0-debian-emulators, 587.0-debian13-emulators, 587.0-emulators, 587.0.0-debian-emulators, 587.0.0-debian13-emulators, 587.0.0-emulators

Index digest:

sha256:d9c7d63cef54216df0088b5f5e6aef07dd8b41777c365669874e68448dcff367

Manifest digest:

sha256:74f6db73b48d3b863d4543a8b92f3f0568251ea0e43f9a10bd50a914f4ecdebf

Size

321.03 MB

Last pushed

1 day ago

Vulnerabilities

0
6
6
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:587-debian-emulators

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:587-debian-emulators --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:6e43f03d5c9a20dbea08c467d244ada2ed32a4014828e18fb398f91d974f053f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:6168bf0d8be17c16a3d54c030ed22c0ac50eeb7a0e2f1769c4e5b34de5a1bfb5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:fb4411f5d1dc98045ae990ad527e1a84c28d539e84537c7f8ed42ea02ec0d8ad
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:eb919501f5e0d5b7e1a43293d62e9c258e5932fd064beac57cf4da59b2f57708
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:c84a872cc3de0ccd1ad28c384ff818b200cbec68f8fe94308d3d109ebd5271ff
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:2090475f6efe3d962a7439e053ad0248b49d1938a2ea01f1240dec471fcba32e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:5436fb48f5f85c38049d8fa732a0150d7876f39b2153014aadcaead5d38ff64c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:a86fb1e9bee3be3291d837dfd3d0a1eb0cb4c6379fe2351d41add81f6f62fbc6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:ad7f880eac2c4c7157757093de02b3fa2b9467739bb6db8a7e4b913ee58cbd96
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:e03ec7d506927d178f8585157966f27cce3d9f5cb1c8c71885c6c6cba1f7f130
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:02e1ef8303e22a3b6097ea296239d64415fb72424f41e1ace2857ac3d75a2d14
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:daf4abbed9886d910c634ac23353b602339d6c4fb0f2e7b1e1780be026499cf9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:183aeea8703179e0c3081c0fd3f42cb4a3ba23be0ff304cff76ecac818b9c501
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:838364bd0d3e6532383b4ed0c1195ecfeb07d97c85f760418e18bc5f2b6a4feb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:ae541e9e7e577c9a8f36e711f0e19b4563186223069bdf4d13779a967ca9764d