Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 587.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

587-debian-fips, 587-debian13-fips, 587-fips, 587.0-debian-fips, 587.0-debian13-fips, 587.0-fips, 587.0.0-debian-fips, 587.0.0-debian13-fips, 587.0.0-fips

Index digest:

sha256:0a3ca59739a06f1622d77f33fc6e9df04d418555fa4d1082979a187c07ad6a4d

Manifest digest:

sha256:e2e96d919faed84b40ffeff262a7145cf6dd0d0d68da8ca190dd38b8b6ee4647

Size

82.18 MB

Last pushed

24 hours ago

Vulnerabilities

0
1
4
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:587-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:587-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:82f3639f6afd00b09e4703dc69b4632786423cb7b0d285626b9b65a3fe2ff0eb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:f35c23f78646a88c8de1d906c874ec4096722375783f33fc1a5d5fd2787e754d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloud-sdk@sha256:d236bebf476fb4d7100ad366bd4f5cb49eb40c1338e1310dbc5f06b65545de77
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:328557df04ee8855952ba923867404fd9c74bde85fb8ec29bd1bbccedc4ca8ea
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloud-sdk@sha256:8d801ab82277daad9a6bc65eeee35163e95735050a6983151e87769c22c88dea
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:5d4d642dc36bc0159a7bfabe099abc36e4918b7908dd4c4ec8ddfd042dfd06a0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:f4e5295a74cb7e53e9d5f62a0b95cbb673423f65422a6dfdbeb304c0e88acf78
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:a76a565b2bc7633c7f3e670fb421e51f876d15966a95c170bcc05d7222a28170
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:6baff88cc71409c25a9614d921c232cb18824a4001010964b06c9a59e09d40db
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:e0b7d4a6a91c2b6174f875820d516529516e6ec2a9f134ac14b8a1ce97f45ed8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:bcb4c631f7c71cc57a5a48bc9f9ddd72ccf707a8c3dea89c42bb5adb779dfc57
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:a28970e5ebeefcfd5f78cb68d80acb338d3f28f591e12886fb0b5d38d3e1c838
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:0a6c7e413ae58600ed042c14824d8596b6d9b576849b9ac13aff261a61151fdd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:16f0a283e33f746f0abd909daf4438d8560232ac4bf90f5d1a078bed478b9a50
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:0bd820bf886bdf86296f828605c8d7b9ba20e733a4547054699b68bb7fb0810a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:bbb22c33222750c1eac1e0e9cb268e6afb80c4d55a80e49d3213276071992a7a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:71eb54fc13d0a0585d1c8f00b2475b79e4f2c0f006315cae6a8cefb76062b5c9