Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 586.x (dev)

CIS
linux/amd64
debian 13
Tags:

586-debian-dev, 586-debian13-dev, 586-dev, 586.0-debian-dev, 586.0-debian13-dev, 586.0-dev, 586.0.0-debian-dev, 586.0.0-debian13-dev, 586.0.0-dev

Index digest:

sha256:7e3dbf0604482499396b405fdf25d64f8fe4a891dea3148343a25bd00e5d4fe5

Manifest digest:

sha256:34348eee183c99f9053a33be06d786d2ec9d911e8d36bc15b5494725026674b8

Size

87.65 MB

Last pushed

24 hours ago

Vulnerabilities

0
0
1
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:586-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:586-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:1066b99f00b9ff9d228b0fa122ddacaa0fe6942e1bec31c5753cff265a2ad797
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:51e2e2b5f721116b63a82dfb597a62518c50fb3fd16662ed10fb9bc141f88144
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:7da127c4cb908c7aaf565fcb88a1ca442d58e639283f6ab6d47f40ed863b669a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:8dcb6dd3e8f3194b7017b3a35e292e2a4be3c2f73b8934103faf65607fd208de
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:eceef6f428c2a3a5b4b843776b0ec83f17137f78ffa7976094d64c7270015084
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:025535a6361d7276ead704e5e23a05c487b39e3cd9ecd5a5196dbf2b2b5310d6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:e1468e30e981f74fca7a9e9d33ed5b50b2560c5c0d6a8ec3d34f394b72eaf108
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:987ddc8461957b9e2405c53faa8c61e0eb23716e1c67402c920227d956251ced
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:5ebe2049462a9d8b4084e93efb8e43e2121bc053b7698eb7c2904631f930ad9f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:2550b47b4385e0daf6afd1c890f915395e08776d3d383b3a976f75f43271337c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:b2af4dbd578923b93b3540da2967d8eccb02f41ac238e4be1ec9d3cd247802d9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:fda7733d4fb0eb87d1a487644ef6cb74a3d181433cb46bbc38a77d36ac714358
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:4560f067d45ed8d32fd798ca3d44d61518512ba42dfae40b8b3b7a744605e733
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:5fce6a185ffc5be2793d60eaa9f8d2a1382ae392aa566ce07328253d121f0240
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:949a5170f8de4e7b97cf82747833bf329e62fc28eeefdba83b2fd53427974209