Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 585.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

585-debian-fips-dev, 585-debian13-fips-dev, 585-fips-dev, 585.0-debian-fips-dev, 585.0-debian13-fips-dev, 585.0-fips-dev, 585.0.0-debian-fips-dev, 585.0.0-debian13-fips-dev, 585.0.0-fips-dev

Index digest:

sha256:495f1ef459245678ec49ccc05579bdf67517b1f61c999b1e7385700aa6c44a30

Manifest digest:

sha256:235f979dc43e54f95a454da73ac79466dff186d513c567b95ec399c1a9086246

Size

88.33 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
1
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:585-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:585-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:1e88eac8ac1569b5ef89b68f9d2ea650aba0fa216d9382bd6cba556ca0bfe4b6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:2bba7d1951326564f2a9d0119ddc0c244973ea9ed0329c92971676b6c5251fbe
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloud-sdk@sha256:915a4dd43f1eb2a3f8bdf1df1c5d9739dfa8447cabaa2e6e3522a7c2af51d927
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:84768b3461857d96121f349730c1f1803f2843fa3d234454d3db9ba2d2c8e7fe
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloud-sdk@sha256:41baf867a19ec4f5d6c4aa4c8ec6768d70eccdcde7eeac8292a336fac89de572
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:6e1250d873c4e9b5f83046244bd7ca3da82859d9a0f17f603d4eb602e5a69b07
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:b227b5c71360a44bc59acf900169aebab91312cb8907af44c32b3dbac9448db7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:a4dbc1bc2ae03bb5a1f25b9bd3fe7e4ef5aefc6992e496aba83131961b45f0f0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:59310cb03cb891c5b44e2f53cfc171bdcf0d2a9598973f60417eeb0cf111b6c1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:87ba8021c1ea238e93e1c23fb1a6c5775d67db405d6ff7dd4bc382be737f26a1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:b91969b918fde8006a8711fa3010af3eaaf19aec034797d3b4d10946b225bab7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:baeeccaceecdaed366c1975ba149aa10fe0199ff3143cf0c808199e7566b00fb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:2c60f2afe203c3507c18379f483e54d5a2a25422df65120c905d3c0023fcbcb7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:48980587651071d0a611c7419a330564ed969a8c3fef7c468b102c38de964805
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:1a63a8eb9b1bfb760d4c9b01e52e8bb4537b3c37b3d4376cd2573045dcc277ac
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:ea8bfb684a9fd780f882c1c631733d238a2f30431ca018ebad72f297b8e03f2a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:8f76c3c676c71157755ec093a7e0522596e42c7b51350a8829cb7f8815f2b35b