Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 586.x

CIS
linux/amd64
debian 13
Tags:

586, 586-debian, 586-debian13, 586.0, 586.0-debian, 586.0-debian13, 586.0.0, 586.0.0-debian, 586.0.0-debian13

Index digest:

sha256:8726286285e5f9b017f2ef4d82cc4cc6cc3a5b5a73b6dfb90d5629bfa89ed52f

Manifest digest:

sha256:7d6da6fc61c50e16cf6356977d7150bc651d8b6a8ceb10ed2f1f30152a467937

Size

79.74 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
1
10
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:586

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:586 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:7eee97d9cf494da55074d05533b9dc38005e87e42e342ad62f4a40a2445add66
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:a596fb25c8c07622a1d18fb683ce6578355b10dda756b7180711bd31938d941f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:260a0ff0693868a30567ee9323f1822703cf038089bfde0f81f642ae1fa1ac4b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:c6bf0e90e397f4f8babb95f4c02e9e40751faa4575891176c32a24e4c5671d62
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:337c58eaa70a0c8f8183eb8cb1be07be0d644638db3eb7f3dede3df79b1a0fac
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:64eea1b7f7b50ec54fc26894f93c85387cb2bc2a9af07d85664a6056c5588dfd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:b9292fd429b5c7083362c3b24ff2af50d5f715e2c7a222ceb948821c70eba54d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:2eba0398472b841a4aed7e659a2592e96db7bddf1fcada28d57234db10242e3d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:5c4978a919fd0a3cbd14fe07d60e4ac0f5b4a4d393bd65fdfba7475156fa4ac9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:164a7194f68f99865943fddf74ca21656f252a124299e7be259071b29a196d94
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:2ab425aea453453b084f4abc6acf4136dfbfc23319af5fefd81c15513616abfd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:72d51c2e67c43f2361f5900f3db2c8efd4f7d3b2df4900779282418b4340a20f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:d16cc52ec9e1006e811c67fe13e76bc60293093bf6740501f4420f94838377e6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:ca87984acd09b2327b602adfdd76596d092af2e5dcc7dfcfdb5c3261e4e67d64
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:14e5f5a20284c3ca15e45daaac33fbc0ee3779d309a98ee9188b0738d4ac7352