Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 587.x

CIS
linux/amd64
debian 13
Tags:

587, 587-debian, 587-debian13, 587.0, 587.0-debian, 587.0-debian13, 587.0.0, 587.0.0-debian, 587.0.0-debian13

Index digest:

sha256:ea4ef0eaa8df75c5deaadae6e55f9be140c9fc97b0985c79f51e4128428a40d1

Manifest digest:

sha256:832d98378527668e962bce6cd18466dde23cb06fa694337cfaee463928af0f63

Size

80.09 MB

Last pushed

15 hours ago

Vulnerabilities

0
1
4
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:587

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:587 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:ee5378f668916d38d5c45ba67fb0ed75fe16b0cbf857b5447a3697eba9b45d10
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:c7982af5ba38646e2936d13b9b4c5aec13af6725507ee18db329ee5a0808bf31
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:7cc8e7ecf20156534f1f0a5030b58d9ca661f820e625b93458f841b7ff1f0523
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:98aa875fc4697b0f070fa885900ab1b37b71716c98755b17103f61cccce5463a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:5d9900043ed64ff5233d91e46627ee51bd458882a98b52491d0bfa532de6e8a2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:ddb3b1b88e9dd78769a6338c59c9a0e43df31585d13495d7d7e1e55f2a34bdde
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:4104e1b159500051730f4d3a2ef361b8f42c5bb7ea0a5680bc3bc5f81855caa0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:d103856f8c68328eec71c81b1b9dc983ea6162c0694f3983e775c699d1877132
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:f0d73250e58f701eaba6ea67360d3e09f3868bfc0d80784886788db9f41d972a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:40cb440aaf9be0c783f5459b33c66713086bfc0963ad94aa3d48ab96f9426360
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:d46c4f44325f40f095a2c232b2ada1f98a14f81952beed101014e7944da0e2ed
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:d4861c721e83e94dd7620f7ac22cf6e0e9f2930f674defe92560cd2cc5f431e9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:f50658810a0ed2a699c2b5aa362ba9ba2c2ce427f8010fcb73601ce287dd347b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:a74afec0abb63212f0cbb7e1474b1169f00ed074c7ca0f984a22b4d262dcbaf8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:39da0927117ccfb62887b831533fd1c4b1a626eae921491ccb4e64ebbf7261ed