Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 588.x

CIS
linux/amd64
debian 13
Tags:

588, 588-debian, 588-debian13, 588.0, 588.0-debian, 588.0-debian13, 588.0.0, 588.0.0-debian, 588.0.0-debian13

Index digest:

sha256:bf5d9f52443c7b479abcefa2ca89817188c028f79e84960cc820b020ce1ff6b2

Manifest digest:

sha256:b76dac5916ffb4fc317ae90a78d30e67f5fd830de53849c93405294e66ce924b

Size

80.13 MB

Last pushed

6 hours ago

Vulnerabilities

0
1
1
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:588

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:588 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:b0250dc0a281956682785e73b4d662d0b75d481f820a7928a2372787f4121a7d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:3f694de25f92ba69c5ffe2b80f03155c376ff2f7843b09eaec304a972427413b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:5a20d391df19364017eeeb6239242290aed147a988734a8033594b54b9534b1e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:47fddbaa5f4dff82b9aef2fd4f72e96662e0f0d862959c6b477513c031963d89
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:c34fbe4b57dd2357dc38ef1bddf36f9e5904c83bb3ffa22cd2b086da773a59f9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:51730cf10c743b2617181eda5da2139d8b21d3a6e73e0a720ed2de2c64f0b2ca
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:50d70f043a70ec88ecdc38bde13f1dfc38583603afe3826b738337d0f38180b0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:b63f054423c8623769c0dbddd9db6363910633667cc1352bf94276e67721ecbd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:53a7e7a54442a9386219dcc1af01ed5331f2d1aa9c767375913604e582393131
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:e9f8f939b3a036c5b224db6e7345b51478ec5589a063265354570cf1a46e9977
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:cdc8010195ec72c4047009614955e66337b202abaee789840916ebc3730f1b1e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:9eb7dd18fed1743f772e86aba6c308a9c95b8564d9c10bbee44153dd3b63aa76
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:69cabbc7e64bbf5390aab236a905d738b8dc9f5f1ba117500ed826497e655406
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:3d4998e55caf94c3f8146c65dd4dbeba9320aeb564c036cf42820d5590117dc7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:f40b1686373931f9b207adcc10665cac1ae4f8d97c160cd4222e018c68c757d7