Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 585.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

585-debian-fips-dev, 585-debian13-fips-dev, 585-fips-dev, 585.0-debian-fips-dev, 585.0-debian13-fips-dev, 585.0-fips-dev, 585.0.0-debian-fips-dev, 585.0.0-debian13-fips-dev, 585.0.0-fips-dev

Index digest:

sha256:312dbb25ca01c41ae5da2478ea06b00b62049fbc870513e2b32c762090bf9039

Manifest digest:

sha256:ee81d35159e2cfae89d5c51f52ecc6adbba9535b31fd1c708cffc4e7d5c90616

Size

88.33 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
1
12
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:585-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:585-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:29f5a771a7de2da48f854b9899a9b014784fa6ef2623c1177cc20b614c405280
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:abeff8bd5655cb65c4fd8e16490c3a76b2cc6b181ddbc80d1e56b3451350d5df
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloud-sdk@sha256:e72b85705fe6e5f7cb1d4f406cfeb0e2a17428c65aef29a830c798e55ca187ae
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:23a92f445c76ec288ceb0dd538207584417487c7bcd054550f03dc58624796f3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloud-sdk@sha256:29871391bb1ba6165d7f9ffa96c1741ac0efe6474c7231e57d947fe098b61dca
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:82692ad63c63265a95b1bbe4f9ea2743ca6073d18c18a9ff60b0d5cec33f7ac0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:79a08954285e6ac52c13e8c9149abc0ac71f9a2623df6663bbcc44b77235c4bf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:5d947cffc55591f2cc56c102b447f9ed8a3c36343eea181cbc0b7336daa28980
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:9ad9d8c2293c5eda1e729c096cb9a3f125e24e3becb082376d7046dc9dc2f21f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:8d633ed7ee17322a1dc2d2ec9ade9a14d45b288b8bd8b8c646dd1e2f8bf555af
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:0694d9862dc4deb8cc37d9a8d543c601ea87dddb067bf2ccd74a197bd1563340
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:35ca8a95e3762051f22071111a7459b3b1008e7ba0410c8df5eb20dba1487f41
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:dd3e52347f2acfdd0d9977834e48188b70fce3c9e6469ce9bfb5ea278bef849c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:72d2e5d73b032bfbf3c615d8fde78aec58ff4910e3961d90aab90b34b3185f46
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:f8a54913e1e728afdc3d2340269d9afbf21e0d9731b11174054180b8683e03c4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:08f9824f7a270332580ff348471e03ca836f6743ff41044eb802807ab401e049
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:95e6f847ae8c79f1b7b73f4dccc099bcd1a2aa06327b9ce8dc0c3dd792951a0b