dhi.io/cloud-sdk
587-debian-emulators, 587-debian13-emulators, 587-emulators, 587.0-debian-emulators, 587.0-debian13-emulators, 587.0-emulators, 587.0.0-debian-emulators, 587.0.0-debian13-emulators, 587.0.0-emulators
sha256:d9c7d63cef54216df0088b5f5e6aef07dd8b41777c365669874e68448dcff367
Manifest digest:sha256:74f6db73b48d3b863d4543a8b92f3f0568251ea0e43f9a10bd50a914f4ecdebf
Size
321.03 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cloud-sdk:587-debian-emulators2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cloud-sdk:587-debian-emulators --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cloud-sdk@sha256:6e43f03d5c9a20dbea08c467d244ada2ed32a4014828e18fb398f91d974f053f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cloud-sdk@sha256:6168bf0d8be17c16a3d54c030ed22c0ac50eeb7a0e2f1769c4e5b34de5a1bfb5 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cloud-sdk@sha256:fb4411f5d1dc98045ae990ad527e1a84c28d539e84537c7f8ed42ea02ec0d8ad |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cloud-sdk@sha256:eb919501f5e0d5b7e1a43293d62e9c258e5932fd064beac57cf4da59b2f57708 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cloud-sdk@sha256:c84a872cc3de0ccd1ad28c384ff818b200cbec68f8fe94308d3d109ebd5271ff |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cloud-sdk@sha256:2090475f6efe3d962a7439e053ad0248b49d1938a2ea01f1240dec471fcba32e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cloud-sdk@sha256:5436fb48f5f85c38049d8fa732a0150d7876f39b2153014aadcaead5d38ff64c |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cloud-sdk@sha256:a86fb1e9bee3be3291d837dfd3d0a1eb0cb4c6379fe2351d41add81f6f62fbc6 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cloud-sdk@sha256:ad7f880eac2c4c7157757093de02b3fa2b9467739bb6db8a7e4b913ee58cbd96 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cloud-sdk@sha256:e03ec7d506927d178f8585157966f27cce3d9f5cb1c8c71885c6c6cba1f7f130 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cloud-sdk@sha256:02e1ef8303e22a3b6097ea296239d64415fb72424f41e1ace2857ac3d75a2d14 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cloud-sdk@sha256:daf4abbed9886d910c634ac23353b602339d6c4fb0f2e7b1e1780be026499cf9 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cloud-sdk@sha256:183aeea8703179e0c3081c0fd3f42cb4a3ba23be0ff304cff76ecac818b9c501 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cloud-sdk@sha256:838364bd0d3e6532383b4ed0c1195ecfeb07d97c85f760418e18bc5f2b6a4feb |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cloud-sdk@sha256:ae541e9e7e577c9a8f36e711f0e19b4563186223069bdf4d13779a967ca9764d |