Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 587.x (dev)

CIS
linux/amd64
debian 13
Tags:

587-debian-dev, 587-debian13-dev, 587-dev, 587.0-debian-dev, 587.0-debian13-dev, 587.0-dev, 587.0.0-debian-dev, 587.0.0-debian13-dev, 587.0.0-dev

Index digest:

sha256:e8c332227a79bec4f2f87501d323cec99902661ad4c04d39be0fa05a5056fd0a

Manifest digest:

sha256:2ee53a16777f9a39836b942364ab5c15c1164e6ffd4ad5b823ce858cca2caf4f

Size

88.02 MB

Last pushed

11 hours ago

Vulnerabilities

0
1
4
12
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:587-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:587-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:9fa2623c9042f7ff82150582eb467be9154d1d2a123582473b08325cb266a185
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:5ecca7e969dd3c6170f0650296bdbfdf33b5a3326cd421fe6ed9305022bb2c13
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:645c23d0d987f8db523c48e9e0765ae1dda18356def0e043fb109b95e6f57ad9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:085e3f579bc28567b3c326860933f1339cb4f2482b3a01391b684c87e67c7451
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:d4562c4003a9cf51929f9a8e2c89172a0f7a55db3be5d3ffe66e727aea8a3393
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:892c4dae858721caadb85e8a06b9b49eb837d68a969c83f5c0b5a1c4a6d196f2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:9397f86fca1c7221132541f505a50de7732e3e1237e36b68edc8db6997fdfa0d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:26f06312160ee4baf0b3ea19dba489506dd65bcd84b1aa05000586eaf2c81860
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:346878f29bcd0524daa02514ed5dff8992fca5e80dd3596a4872030e870d4a55
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:41eefd38476ae08532beaa0b2207c3d0bd7571388b9c8ae0e6f043384046ce88
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:2e4f216c486301109cf69cf8eb3f083312ba6216cbd9b6606f69eaa45dc95a60
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:34189499dc266809f49290b93bae10d0aa5c8edc937c062e650bf20e64f6ff2a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:e685bfd9bdc50ae6da1f10fd54bf22affac03f46219126c773b77b66a371e30a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:2edfff2cbcc3a43fa25088fe2981c07433fc164b7688ecfb236d248316571063
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:91252b0cbebb9c0e884abd1b82177cde71cf7e41fad09b2b5dadb611871f40ff