Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 587.x (dev)

CIS
linux/amd64
debian 13
Tags:

587-debian-dev, 587-debian13-dev, 587-dev, 587.0-debian-dev, 587.0-debian13-dev, 587.0-dev, 587.0.0-debian-dev, 587.0.0-debian13-dev, 587.0.0-dev

Index digest:

sha256:7caebf1b0347bdfbdfcf719b9730bdc321e5ea847a2340607d7f2908c23bac28

Manifest digest:

sha256:1e8257a15e0d039043cf928e1d4736b3b9fdc911ca4f1908bebd3330087b3843

Size

88.02 MB

Last pushed

18 hours ago

Vulnerabilities

0
1
4
12
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:587-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:587-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:d9318ed6188e325cc393eab3e0734fb3aa04c8c9176caf6c671c488c6466ca67
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:56c375251c498028904040cb42416fd8a79549f008b673b6b655f7fca5038618
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:6acb8f527ef88256319c46c94d85daf2537ed035070ed2fe181a33975c4bbbc0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:a6371d9fbdb94573a8847dbf730c33ecf56c3be8d590eae5e6aeca09195befc4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:8e9573e4bea3abb7e20bc0fa7bd7907e5fb87da74aa780221bae362b02bde4a4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:614e780f423ec0eb3819c7b95239a56067da1c11128b91eaa8c5bb7e930ef088
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:3c551e99c0e60e4b942cdccb7420effe3883bf0a089d4c8a4c02211e14192429
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:6840582e2dca82779dcc293e9a2ce70899a6cb8acc16cf9aef48bfc22f79f612
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:71b8a33eacbd1d63cf4e946afbe253a9f6a3ce8963ab6334e1dcb0e693c576cb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:e95dcf263c810b1765f6a67e57a28cb1c160a9f96cabc4902442c2afa33cabcc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:174a121770e77f3aa3bc360f69b1de8db4064f1cd8bdf8156fd2b4923c56729b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:ee827052391c32c991ae81f3e8967472f57ca0b80034634958c7767d7eff0728
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:65913c6e68368cfd3062a5a37185bcdd41f3d624bfbcee2959591bd95b0fc75c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:177344845d8dc0728324d0aa14b0e129355572374faf28c751565ff522f26548
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:a71ba562e851c9cfb2322c8b4c1c5b01a322e355d8fcdb0deacd45b61569f476