Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 585.x (emulators)

CIS
linux/amd64
debian 13
Tags:

585-debian-emulators, 585-debian13-emulators, 585-emulators, 585.0-debian-emulators, 585.0-debian13-emulators, 585.0-emulators, 585.0.0-debian-emulators, 585.0.0-debian13-emulators, 585.0.0-emulators

Index digest:

sha256:fd3b590cffbd1c60397df785861b602ae90e2fe233436be1453fd4960ecb256e

Manifest digest:

sha256:0dc18ad2225200b859b8fd524f8624cee98588c0f619eb57b3dd63e20df6e4f2

Size

320.50 MB

Last pushed

11 hours ago

Vulnerabilities

1
4
4
11
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:585-debian-emulators

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:585-debian-emulators --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:a605e5d57b148ef69ab5c719c94e88ccdeeb6fd44376b86458251bc8c0874d74
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:b1aef601ba31e4aa9a4d5c2b3d901e38fabbf37cdd497b6c4de67fd77d9278d7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:c6268ec03e5e69d8485f3af45d9227088e36c1ca0ed2b7d3240a7dc134c8c0f4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:58c51069554b55f0dd6f78fe4a92e78f6b418ad08e25b9411dc5e1f7ce08525d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:b592ee7906e8aa76c62628c6b37a4f9e560cfc8a5ae7529abecd233d00cdb755
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:d39b9e15abf7ea0b2f92dd933a6389e5a40aaf3f1e4431c9611d247889c5543d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:2ee723f08a92ee60a660878ae856f60276cc9f89fdcbcce4ee796aaf54fc7694
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:dc0e5a3ace37f863f6403845e0a2eb3456b24ac7002b2ef34424695c2cbff4c5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:2087a33f07deaa12baf1caa62eed258a38e7b78f74055a221acc0da0c9b22eed
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:4681a9150ff063f89f5e375029ba5d416810a6a477fefbd17c2b8abbd4ff146f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:d3dbe8b77bdf7a0de4e1f752fd51c02fba79e8690f2b8fb9de4b090349357505
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:7aab5e832d7c7d28d7c9315990178428ba0368aaa4d6fcf753bbbe19a73acb5b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:b5b35fa7703e2a7eca2b29e992e16142e0f69d97a4249ad1756aa5a020658ca3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:ad2a10597057fc5853a5e29f4f72b32f1cd93b0c3de0216fe5a2a6015d2d4a71