Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 585.x (dev)

CIS
linux/amd64
debian 13
Tags:

585-debian-dev, 585-debian13-dev, 585-dev, 585.0-debian-dev, 585.0-debian13-dev, 585.0-dev, 585.0.0-debian-dev, 585.0.0-debian13-dev, 585.0.0-dev

Index digest:

sha256:576c6d7c72c2c5584f890d447a36b3550ece74b1116bbcd7d5497370e6bd4947

Manifest digest:

sha256:024f6bee7b04b0feea62bdb06910fdc3f68d74474c4b0fbe0d543591d27582cf

Size

87.55 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
1
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:585-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:585-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:fa97a0101750fbedafc941f91757d42759bf65eeb4e49964ea7f0dc4f9ad4b5e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:1a87dd52361130617b74f392e1368bedf7e105dd6bb26d39fefa6e6de4d08b0b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:2511455a6d4d2a8d488d615c5b1143fab4595524fae44e8a0d97489c0af0ee9b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:f6140485a4b52279134b8c710f9753e94213addf691d397c46199f9f8bfdec9b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:b64dee7a06e9c528db95939fc630f6810f25feac244b87f619286fbb3f3993a9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:8928e642de2d389e3c570bc5e08bdb016be42f3552d24ce54805eb0840ebfb4a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:29ca678a897807e1e101f3315d53d58f029a0bfc194b33649045063f4dc7b55e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:155cddcbc2004129ebf546d9875845bfb745c96a247226da0e892470a57bccdf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:4eda299e917c94788c41cb7bdd8e7992a86c5397eecd3be7ce841b4d4817fae5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:13589209f381c68d96b4c4f0179360c2b791c0810a8a59b9f349dbddc239a6fe
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:b927541b48bfe888d11307e8fee952c839dcbbce4d223e5ee65da3d71da7c0ad
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:a8c7a93e530a3176739449220df9a3bc9b5564a85be36372778852f857afbe2e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:861358314a400e5436e84fbff37ecec21d71d6c637ab2b6f2ceab66bfe981c59
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:95712da807b521ff4b180a17a82f70bc0b45ec133a8e24ae00966d70742627df
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:ac4d000f97ad3e145bc10fb75bc2f93faed53698f350d061afb59f8941e79101