Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 585.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

585-debian-fips-dev, 585-debian13-fips-dev, 585-fips-dev, 585.0-debian-fips-dev, 585.0-debian13-fips-dev, 585.0-fips-dev, 585.0.0-debian-fips-dev, 585.0.0-debian13-fips-dev, 585.0.0-fips-dev

Index digest:

sha256:49385725518f5faef700fa0750e3e92f5f6bbe5e187373e4ae9b5de1e65c1779

Manifest digest:

sha256:01f0e80b41f60cd994ed79086cccc890fb6da62ca9b2063d8913f9b5c4aa9cff

Size

88.33 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
1
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:585-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:585-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:f46a30d5cd12769c953690545bde2b375e11f6d2cbac99f9601c73766c35c936
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:aa8a3da37b275d36629ced8d4c61620eec95585f4745dc4d92638e6e58c191cd
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloud-sdk@sha256:23df1d59290fb0fb4060990771da4371fc42a59d94bb3be7687e0ad3f963cc33
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:036b22bc8cabf5cda2adaf18676467bdbc847a265a5efb73e6b6a639706a61c2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloud-sdk@sha256:db40c19359d68de86df9f119ea659f587a089666eddc9c542e2b4f4f1111d22f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:7077092730302e7a4e6d9c6060531b700322ce4ef243270c36c615aada25db0d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:237b57c92ac4ee28ed47ece1da6e5970944c97ff214ed96b1ca3c364c3b12bde
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:0aaf552b651775811ee2e9c944f26d6a3443e739a9f6ce42c01fa8b798c3b52a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:825403a61517de3fc79fd2c7959cd80ef1960f627ca007440b96135de464bcc0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:5d6f5bba9973a413ea156f828e1570acf6fb5584394b31e8588b01de40138f50
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:f55a05ac894b7a7c4fdc9a0705211f930333c7d0ee4620664cb43dad74a2f903
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:0fd3bee5a855224a2af062d8e63e8f0d97ee69462d7bc56d737dfcae45da801f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:1f982c26980fb3f40f39ed7db9a2bd83939c9b142806e8c924ce71910bb57076
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:8805f19c16b69337775637696cfac2300f43d6e6e01c334171f58a3eddc67699
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:5d581bb99931ce4fd485d6f71d4cb23c1969201493bcea21323797a7e76cffb1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:1c67e16ee1387f07461b5888e4334b080814411655affdb10642a52326aab8f2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:64b4c6ec9f575547f8c1fa8db60dd4b1a77adbe9ae4a4e55a75977ed227b09c3