Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 584.x (emulators)

CIS
linux/amd64
debian 13
Tags:

584-debian-emulators, 584-debian13-emulators, 584-emulators, 584.0-debian-emulators, 584.0-debian13-emulators, 584.0-emulators, 584.0.0-debian-emulators, 584.0.0-debian13-emulators, 584.0.0-emulators

Index digest:

sha256:29ceaf1193c160bbdb30e9600b1cad25f85c7969ba2600f5f7b0448af5e68e72

Manifest digest:

sha256:22c0bdccd8a422ada58f721155c05c912d50ecfb5ea01786dd5f1546402db85e

Size

320.04 MB

Last pushed

6 hours ago

Vulnerabilities

1
4
4
11
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:584-debian-emulators

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:584-debian-emulators --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:0ae11a401123d9c7af9dfb5addd4b6ec531f0f67c9e3d8f10adcae9e5ae17ae8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:045537cbdc9aabb1d7ecc7961c2fc65bc0fb924887c1833da23705f5871acd70
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:a3044cac9efed47f21d819eeeb1886589a5526f69888fa63ef1a4d0ba9a897aa
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:f25f7d67108cdca7997ca0b918341667b950fabbc382e4dda8d1fa5f26790faf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:ab789b5578654d4aa9ce1f343a68af783f7c4e37f3e020a8f17a7d934630eb07
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:8cd4b630f414089f0eefd2e0484947b96fa6f5b6e17d48c1048f47bf2961af28
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:ba194d7bea5c6304b2a45806828fa4c65025d132a950b736a7654072ff120458
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:a4e21f0efa5c0486f6ec0902cf8cc832bb997a135d8b05a018980e210b5571fa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:a2656970f598cc8c3930a7d32c300a8d98ef4735ee377a3c2f10bd3a6f87a4a2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:51b0d4a35e6b17df9c976d4f20b315f2b30c0c62b3f8314fbdc6cba446935f6b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:54273301e701e23a5ea284ed3e24375873575f1b51b6f435c8368a65e420442e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:3b502b29f0234026ec1a56e02fef5cb1bb3942cce86376d98314260ccbe0dfea
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:9e3e0335fbd86b841b52ff7e89c372799b5c7c93b7523386eb7ea84cdcb8e030
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:43fb2862924b2b2a4b478bd1805a1958b955b84a4ceeea580d735c7fc49d75e4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:b6e5601229f5d216ff474837e93509393212ec1b8749592cfb6ccf369a428f23