Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 586.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

586-debian-fips, 586-debian13-fips, 586-fips, 586.0-debian-fips, 586.0-debian13-fips, 586.0-fips, 586.0.0-debian-fips, 586.0.0-debian13-fips, 586.0.0-fips

Index digest:

sha256:962cc17c3d972b83077ed4e73da224bd108605bcefdf7ae5552ab23d03d5241c

Manifest digest:

sha256:06989a2d7fbff11c8e83decdc13c61ef36a3e888900f2b358566b60753084b94

Size

81.82 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
1
10
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:586-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:586-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:4950f42856ee23382b90de65f1494e95da3449f271520d9096a68bab932fa9fb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloud-sdk@sha256:bc69dc511ac1dfa3e17058d3750beae331cd312b592fcbb849a5f7b27a0852d2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:b222edff6466d461ee845f3929e262ac9d07a1b979e6e6236fc3918c8ca39f6e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloud-sdk@sha256:4b6b3d124280115692c6c2eb70a234a774fdc42384896724994d8973e6b33a20
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:25dd7d7275d1c425117be1c2d29d8bb550d5106e08044da8e7f7562b26c8f13c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:702857f693195ae2436b8d0d676008d64437304a3720e0a7887c27e612c24c7e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:d4617c4a7f3f7b80196d7278a03948222d46b45438c1f86f2d1c2602add1f020
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:eb888ebb5c90403a2a5f9b0ca4cda5f70bfe574b86d2139fbb2a0305c0400166
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:879c2cf2ac4150b0ee730ef4c9e5beee53d1520a5b2f66134ba2b5d38c64ea77
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:60426cf95ec057b47f3c586f41752a888998156d1888d90c737b00444381354e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:1628b1093a4d27f281893f28242947b5c2602eb7c3ef5205f539ff689f0c3b2f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:5dce3d0349d4b6e842373ab3b4458295f5f0ce1d3962468e3345ff5c3efd832b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:15adf5d7c2c54e59ce07c0d1912cc41ec3d7f510b11d36c7ab22f849efad61d6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:224074efd0ae4fde850535a8449dc9be5c312c9416cb83a26dd01bb95b45bb60
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:3f8077a28373a25bf5b991114d5c3d55f0ac7ceca316dd5733bcaf25f1d9306f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:3035bae58b99cdf18b5cb9b0be8135331d8a980c644deee6979fe4d3809675c9