Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 587.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

587-alpine-fips, 587-alpine3.24-fips, 587.0-alpine-fips, 587.0-alpine3.24-fips, 587.0.0-alpine-fips, 587.0.0-alpine3.24-fips

Index digest:

sha256:5df3f053d34bd94fbdb10ba44705e9a924dcddefec05b6a8b441d991b8f3729a

Manifest digest:

sha256:a70a0869ff5c323c8f6ae7641af687245179e9f99c1809e2bc6d2fd27ef4628b

Size

57.72 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:587-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:587-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:06f97c4e54b19b44268430ea25dc0a22549c44db22b64e7121b445e75531a40c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:e08cda4348a485f5d9259c8588132046cf378960997e506baf955e6df7c252ce
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloud-sdk@sha256:00e591f12dad974d0b0072573b20ba11b24b411bee09b04c5723163f64c4d8d2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:e582461b2ff0d21420951b826c50854981bc2aa5ffc40b45b52c51883c612bb2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloud-sdk@sha256:7de3f71c1ca44eaaf07840ebdc1103405f684aaf0901afe0d9326b6f7e149658
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:7f4aaf176f0b98c4c427c4edb0dfe73fcd0389d338397250a35b6171f85ae0db
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:726479550d8c7999eb8d70c503502285d40ac1c99c7b185b3abb4658a4c8982b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:6eb35d67b53ea241d23a806a9b3e42e6c01d8faaaaa1f86c4caef9521e1fdd1b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:16f8cb74864f0c574989fe6db2211796919289e0362d0698731949294314f5df
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:2f664880b74508d3668186883072fe531b271f109e4785db8446dda2f034f405
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:9f40901610e5bcdbaa00503d56a134b8fd102f546d784091b47a6b3bd094cf6b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:9a4db6816ca493e4a8351bf34c2096009294bb24961090c41a8c93a9a9eb3324
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:125b7e4b2ab1e18585c91a5901d2e33637404966349a3bb056807c4f3d13e570
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:8b7c9417b4201f768ba0db07decded5423e8316facbe7df4808a96adc3c75b91
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:d355d10878e4ed3fe64a25b134897a8709d0639907259e46fe3f906b14c27ae9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:4f30f2cbf2891b7c2f5ac87992b5953d9f77ebc038007a139e63563fc4f9d0b1