Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 587.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

587-alpine-dev, 587-alpine3.24-dev, 587.0-alpine-dev, 587.0-alpine3.24-dev, 587.0.0-alpine-dev, 587.0.0-alpine3.24-dev

Index digest:

sha256:9f926e3c818524c6e660a085820dcff168f4d3b26a0ad8f6a2be0032964919bd

Manifest digest:

sha256:bcc5bf6b66d1cfcf1994ebce4dc08d2fd4e807acdabd0732fb4909a4e216a7ba

Size

56.87 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:587-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:587-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:12a2940eda537582a381fc03335cef49157c92777f2650e1b2396653bc604d6e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:52dc1b1661deb2bf0d439afbaecce5d68730806658a13f0a15e2c6101b25e427
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:89370a55dcc0376d93d5e3609942027c1577cd25e0eb829f2ddbcb4d15777aaa
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:4eb1bb86643921cf177fb2627e655db98b485284b59acbd9e517a3da493f441d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:d28d42c8bceb2bfa1d77ba4106319e755ed782c06ece533a2c9f9d1ba4085209
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:5f599a28c7fa86479fc04f18ddd4c87f5beb35574cd55c71ebff374e22b9b924
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:ed4d9b4c6cf3af97b72b4d25f719a8a04f14834ee15381079ff5de6e35e6beb1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:65500a144a3b95f86f8e1da713a027e89aac93f14c1bac1c734bfb036e84c79c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:cb3b7bb1472785e6b1a33ea395a514f647db311ff5fdf1a333db6680d2f96253
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:c2a9532c1aebf2f5bfac4207c043a43c017f1593d091f2a501a50b45891961f3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:768e200cc1c0be69c7a0bdcbc6da0ecfc6f83184ffba9cb9153675c5fb684805
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:4018ace5c3753ce05b25243a3f47a1db2752e0fcf2f504709612ee7a0885f153
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:f696160449a6017d6d98524c5e164d9d7e0803d1bd1144e31fa291da701c0ccf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:659bb22a37041301643b8301a06c0164a9c7ffb36549bb0d8eb71c13cef469fb