Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 587.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

587-alpine-fips-dev, 587-alpine3.24-fips-dev, 587.0-alpine-fips-dev, 587.0-alpine3.24-fips-dev, 587.0.0-alpine-fips-dev, 587.0.0-alpine3.24-fips-dev

Index digest:

sha256:82c65473422036b74779f3a381c72d2502a3b16c6db7b75fafb2834f663462ec

Manifest digest:

sha256:284fe6dc91e2cefa44280b98d76db5ab4f313347cef96de9521cdb0afe0afdb5

Size

58.01 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:587-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:587-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:5e13b10efd806d8f633185c5fc9dc3fa1be7d1cbd6519dfe777e8b40c1b4c426
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:062944cd267324bd8eba59a9762f36673f7c212b56dcc7e0fb116a3d6935f676
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloud-sdk@sha256:19260e4a8269caaa0af975da19b91dd1b73132546dff2cb2bb06901202625824
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:766a68bd3f69749927fbcec8062c0db40b07f19cd13b1b1654c202cb9a2595a7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloud-sdk@sha256:9f3d0956da3754aa09bf03770126ddfc94d95c325e88f70fdc21bebf90237c68
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:273f6bb8d78d804bca0abdbf2d77bfa2af156fb8832b4fa62cf00fc8931df9b3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:8b80e2a51514504a7258589788b4aef0573889174bfc63eead2a854ad6204d25
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:e4cc709d44a8c96773d48b970288501f73f4eb717001dd36571790ba87b6a572
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:a17746afc466886e5d7cf804ea3452e1002ffb2d7f3e622f1601b3c11343f8fe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:918fcc9c3af206e5f4be76187b5ff96f8a0b6180c2b17fe873ff31782f232d46
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:b20e016944e14894860140c3882d7e8079bf0a71b55f65cc90988043224c78f5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:308f6db1c980bee79bf7038c3f3ece6c5aac162e177106077a113a70d3ec2923
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:ae5d98a52b263dd4361ed3eafa9d32afa28685a340109c21c19ec4feb0ff87cf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:6562948c64dfa5fc728a2cdbd30477b60d041645e5c9ab392c3c815e7ac39870
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:4a5da12e773c0b2b9c078ceebabae5a5c66ab11e1a76c5eebdedb8508fe74145
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:fbd4337a98b0f5c87b2ec1c423b3ff1c6e95f3880a7d36b62793c943a9435d37