Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 588.x

CIS
linux/amd64
debian 13
Tags:

588, 588-debian, 588-debian13, 588.0, 588.0-debian, 588.0-debian13, 588.0.0, 588.0.0-debian, 588.0.0-debian13

Index digest:

sha256:d6701497c16e7522eb3bbbf4efe1e7012a28f654c6925a3244dd63a06546664f

Manifest digest:

sha256:792975b1052084ccb48fae75aa50299ec82dd6c1ca662ad5750f5c8a903e43b2

Size

80.13 MB

Last pushed

15 hours ago

Vulnerabilities

2
4
1
11
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:588

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:588 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:8e462d668b7946b2590db107b05a502ca9f4ab4335e65fff060d23a41123ff09
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:445cddefcaa3cff11ef55ff347c2e6258d95cd96059d747fa0e145509eb947bf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:c2c54db45661310a5129375baba7ee493c8ed0ca30893c6985830c03654db674
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:717e1ae3514883a7261d904977d7089054c95ae572f73992dca552b14829965d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:fe81b13a1a48960a141e02966f9f1eaae15b66d540b6bc967f9a34c90a39fb40
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:00674f6136c07b9bc547085259533c5fd52c9ff814c1f1e72e8594a9a8d3ba8f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:4a3e909aeb1cc57383aac9156a33a004b9da28c4f1d9cdfe6dc6b6f32a156771
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:ca5e33c592e50b3d4fbe0f634463a6164e1f347610aac97c4f8193ec6b92a547
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:b128574a84e91844cb9003e1a5eefc2f0472bf97401d2f2d33fc7e23d3b1b9d6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:141e1ff110db2358e3218ce9ab8a80e35b7ef4afb6a8353e6bc72268e50011f5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:b6f9ea63bed4aed8e10cfd51b8bfe0270101d1af7a03b05ffa2c7651525c2004
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:f986eec4ab8e61bdfe4a80799a7b9febed34830764ec87ca67e12027decdae77
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:bbe833fcc78e6ae3f7a1997fb63ddf7ff8ae108cfd51b25d2802e4db66037086
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:37a6ca1f2d525e4d9b7c4c784730c168ea543a3b98bb451a6d79b5f1da9a6ba8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:7a7e84bcdbe332df10ae2a22215de9aa17046d9a068707f27288480660fed2bf