Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 588.x

CIS
linux/amd64
alpine 3.24
Tags:

588-alpine, 588-alpine3.24, 588.0-alpine, 588.0-alpine3.24, 588.0.0-alpine, 588.0.0-alpine3.24

Index digest:

sha256:08ee104d5c406d6ee1de153bf1555009789dc7792deb45eb2854f63c601e1dde

Manifest digest:

sha256:902ac024882cbdde2b00a7f8b5abdb41cdc6bb6ab6b87d8d571de2e78d042890

Size

56.61 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:588-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:588-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:a6cf21f345f08c72a80604b21987672a3a69fee269c0a04db0a4553846a708d0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:b08a037b316c8d56c656afb0aaa3595cee7e434d4b076a7024f0dd2cfe5cd50b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:68613621a4c68ca14d0ef8c9f9c2cc162521fa8648f310fd96b0391df3a6de7e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:dacc5111585ff21b6ef9186c046d17c0dffbbfc2b9c4551649b9af0ed98096cd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:5a584572b288dbf9940b2ef0e135a4ae6ef8d48b7c862222f1e87f36213ee708
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:5b43e826d7c910fb605e7aed9f95034fe6aa4ccb987c36c6b841eb40f8d091a2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:6ced7a29c44f7e3f987203e3374a362489143f58297a8dd44d213c742ab4d45b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:394a700c9f083a877171dcc4288ca677cc7a2f16b7f84c5d2191f8efbba9e535
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:af79b84f9db5e186ddf77b16c3e92db4efa78fd40ae8e2eaa51caad8e2ab015f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:64a27fd3608bb7f9144e27b567e17b77bb9441d69ac316da8c043261a4d31a93
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:fb4b8abeea8c8d514087a754aa5c679b2e06430d76a9d8755b402704568169f7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:1848b7447b27060a48d3c5e171086cba7ccd66058fabfb8699b0a29e210a97bf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:1105bf4d4c2d3af97fa6e2a6a6c099ee7630aa2fabf2b62ac305c125c9036bd8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:b35b506d50f275b03911626cfb00fe0a2b5fd46b14b5f75729bdc524463aea98