Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 588.x

CIS
linux/amd64
debian 13
Tags:

588, 588-debian, 588-debian13, 588.0, 588.0-debian, 588.0-debian13, 588.0.0, 588.0.0-debian, 588.0.0-debian13

Index digest:

sha256:7411b162fdf66e53a65f54586a6cf20dda1f6f92ba12f786ac44935e51e0322d

Manifest digest:

sha256:646c2204d71a007a0ef52a9c4c10d952b087488a3b7a9f14fa82d2d26d3f7bf9

Size

80.13 MB

Last pushed

5 hours ago

Vulnerabilities

2
5
2
11
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:588

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:588 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:670eece09fbc818d451c85bfa8e3f5597950e8a60a188175c8abadbe8a7a70d1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:07377978f4970034aa6ce164c91dae9113b6b4588735c4792dc3521ffd497d21
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:87143713c1a0ef469e06b2b7dd993542b9bcfaccac01ab181ae4f647832334c7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:678b6a086ddf6c8ab8e04895b31469ca40781827c6dd3e308793180a3e408368
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:4928b7798fec8a4504ec2491306a233f8a70850fb788ce1f7f737e120b57d311
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:799bdfc1e80e4fba20be89a96bdc967ea91d92e9741032eb610ab99db9eeadc9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:739fa6aff5779f0f8b6991d90e9c4d9df27c4445d99af51da1e892acb9e0aac6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:4eb9101b87f0f6ef41da0fd481c2eb15814eca6d162402d3e9e17b428daf7a0f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:925a33affa433fbe8c32ed204e0e157517cdadbaf9fde976fceea20713d0d238
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:1e3e0f9dda53e0240f3492f4a05fb7c355594501ba5e816375928c942e808b41
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:5a7ddf203882bdf06ef852757ab1504c28812da0ba5fca7aa4499dcc8a161534
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:3c1059511d4f3595fd8e3679cb45514be0edf3785840bfb2bb80a1f0da2a4692
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:0aec35c2811b4d6488d7e3f1b1faafaa68fac95acb0b5a50350815884b3d8646
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:b91f8c7aef6a55e25b4f1aa633351ea66c5f2004fe6fb3834d20c0305e231f99
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:6dc01f2346ab23a0f8666ac5cf09c89e0ed1577867dbd4db5ee5b89716e69972