Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 587.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

587-debian-fips, 587-debian13-fips, 587-fips, 587.0-debian-fips, 587.0-debian13-fips, 587.0-fips, 587.0.0-debian-fips, 587.0.0-debian13-fips, 587.0.0-fips

Index digest:

sha256:662ee44f997b3f28b330b9bd01345cc6197e1be09dc2f96983c349f85a61c9a1

Manifest digest:

sha256:af0f51a7ea63afd7c32124ff1aa8bd8ecc488d83957445346b6c8db90646c2f2

Size

82.18 MB

Last pushed

6 hours ago

Vulnerabilities

0
1
4
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:587-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:587-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:917637b376a7a9db5a35aa85d3ea6e6f772f5707b37e9772f8093577c3891678
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:f8c5a817a396db10a3638b7877a6950e60b6fa582b0c25a73943e72eb16ae9b0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloud-sdk@sha256:a05b013b885bcb8560963d3fa72d41e26eba988c44ed954c558881582030656f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:a3e310bab2656ca9aef34192384709a5a1a623e88839dbef5c1199e173dee573
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloud-sdk@sha256:f51022f4f0aab8f749d4f0a1d1d21a42e81d0935f77b29e3f7fd2d21c594789c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:04d99d318b46ea0c85a813cb735d45f0462f8dcd5de866a1e8404739c833705f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:e4e931435905083b02c21856e707256a08ae83c671a3b62c2059cbd24e424372
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:c1ef0cf39c2212273b15b0c57bfb77b0b0d36b21b5969e20cf98d9e86d7791e3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:bbc2e1d4ee7a38482f111cd62330a15560732ad73283fe142efadb5c68eaecf3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:0b05733e2a0ec200a4945c98f8fe700636d13c476c935f0bf00c8d5a55c6c6e0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:ba7009857dcfab5791506199b499bc751318afe6b33567bb6544ae9409c2e24d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:09612d833f7c155da01faa2bdb41af1e820c5dc8bc234400ea132e11d4221a89
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:2f36f0437f3e139548698e5d18fff25608ffa0a60c0233889d8f5d230ea27188
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:a59c19e7f4c5519ca7d649d7490bfd584fcbeac45acc723f1f104af545fe6f74
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:e4becc774d0f4ef8bf93940f7d08cf6e0e1142bc3520606483e940119f779a03
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:cf64a8ab79ee378aaf4840287700f343cd0e42eab418a74cc96ab6b5ae0a1d1a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:10fbb69d7ca06f7d37a787e9c8fe268c91a34a47eaca85442f3f93cec446a6a3