Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 586.x (emulators)

CIS
linux/amd64
debian 13
Tags:

586-debian-emulators, 586-debian13-emulators, 586-emulators, 586.0-debian-emulators, 586.0-debian13-emulators, 586.0-emulators, 586.0.0-debian-emulators, 586.0.0-debian13-emulators, 586.0.0-emulators

Index digest:

sha256:17e053df9bea68eb74bcf0a88df3ed44cf83506dd538cde3c8b28422ac7ad1f5

Manifest digest:

sha256:f806640fa50aac1e7aafd68d43f45bf53dfdf1c79a43eef94fed7666ee42cc5a

Size

320.66 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
1
10
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:586-debian-emulators

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:586-debian-emulators --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:60070f14fc4af40f0f0ff302e4307af44aa450b8e54e389652031ad0bf96bced
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:11cec3c3517fe38bf4737e5e76fb89b28b4aa9c83d33f8e764fcade02cdad8cc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:a528741fdd6c3ff5195bc506b6f502243924870b81000dcbd2906cfb8bd217b6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:0fe8ecb8a3a0d5cdf8f553521ebdc16bac66524d107576adc17b4085eb8ddaee
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:298e0f5a6972cd868ad968e0f60a17ef445ed0ff706fa6cb359a353214e910e1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:27bf80e718fc9e8be3a6a4d01cbc5fa092f40aebdae54ae6214ed2fb6ca0cfee
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:b69d332f2860f92f129c92ce04267d53552aa3078ccecb4f730149e6593021f0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:cd78122cdc3b837431e85f5deeaecd8830196dd75e6892b6b18415f504d39119
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:130ef2256fcb3327df42d73c5b242848083b08f61db15040ae3a55acf561c29f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:aa121605abbffacd262486ab0a0d64dedca9773967b07e209ea4421eab0e2657
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:76a8ca271bc136761aec6d1fe89104b18b4def759a91bdaa9c6ce947fd704097
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:d8a957dddfaa5d506906da19067ea41d95132f1752e6a369ed9cb08fce5dba90
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:33846697ee7ebb431b734f9523355478ad2cff9d97cb4276a33899967f3ca785
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:b9a341b782c72258367c700cc50c2d5a610a3d3f6eed85564246ff238ae9b84a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:1e8f0de5258b3853037570eed90b95888781d61c56a9e8dacac2954a492f9d9f