Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 585.x (emulators, dev)

CIS
linux/amd64
debian 13
Tags:

585-debian-emulators-dev, 585-debian13-emulators-dev, 585-emulators-dev, 585.0-debian-emulators-dev, 585.0-debian13-emulators-dev, 585.0-emulators-dev, 585.0.0-debian-emulators-dev, 585.0.0-debian13-emulators-dev, 585.0.0-emulators-dev

Index digest:

sha256:b08b55f97a82e65c7f75e3ab4aea7a86a16af6fc2c614f24288dc128d53fb98a

Manifest digest:

sha256:dd56d7019a444641e1570fabd9d9ae9cd83dca39505cb01aecca8fc8d11ba8f8

Size

327.09 MB

Last pushed

2 hours ago

Vulnerabilities

1
4
5
12
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:585-debian-emulators-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:585-debian-emulators-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:a6edcf17698c07354d966cc452c76d4ceedd715fa7e1043f221e31e29795ae85
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:358aee5c4ff0040806477913f6e3b3207118d53d76f9e7b5afa4391f3909bb63
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:37085e45f8ce3891e26c1e1da66e68b5aab978c9c02cb10a9c720635e16af85f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:cefe1a365ae3ce27fb0ac72aab0a6f2f606df60004be4960e3d6e71a46b468f4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:dcad034cf71d0ca70da32aa12d01b8a25bfe6f24bb84a329773b78d0af473aa0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:5b9f7a880ceff92b6989283cc7ab272de5aed962d85b7a5c46904b6fc0d3ee45
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:5deb421f91bfaebed5060f9425d10c4825ef7bbf3efc5e2797da56c71ebafd37
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:441421f272384056bb49db3c490f207505b809c0108227c6a3d1baaecb02ecbf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:a353349d68f43557f906104938787715c92d20168d22e8ae7691074998d62c0a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:6c042458c915c64812105f655a583edcfbc84ce00a377193d73ae811da92ef3c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:6bd4a25a88349c8920a8449e8740877c91a4e38d64aa6b98e4d20b0103a9992d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:0359f0c4c94d2f10ced4f521cd4d682059f314f0047a6f008e47fab5bf79d7ea
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:e7bb36c01046f9eaa49e46c01250e545b6c650ac7fb50a780ad57270f199e61f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:e04f795ae93e01e41447a1f64a5511d4eec45e29ca265ce97e2d3cf2e052b2e6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:1acafb8eec7c3f5c2ec540465725f6fe422b56dc8390881e68afa4127a067374