Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 585.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

585-debian-fips, 585-debian13-fips, 585-fips, 585.0-debian-fips, 585.0-debian13-fips, 585.0-fips, 585.0.0-debian-fips, 585.0.0-debian13-fips, 585.0.0-fips

Index digest:

sha256:9f9e193be57c5cf56535428fa17e17f233f69c389e775def2dc87beafa6df09b

Manifest digest:

sha256:600d1dc6183d4378fe87e8d7da1307d43688bff15e1052de0b56b96ff01cb8f1

Size

81.75 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
1
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:585-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:585-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:5bc89d105c19ac1a92f4ab8f1ecad2620368aaf7880c06852d65cc3ce3534594
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloud-sdk@sha256:4385292e4d06acb151347fdd62a85cbb53189a709f9ad8940aa4ae4966157bc6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:c5f342cefdbcfc76a0069e8d9436bbd4b92cc710c9d37a8da2bc65b63309a478
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloud-sdk@sha256:509d096466dd7c30103632d2ed2a5212b86b9b8b3216883f5124ee32394d85e5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:49fea3d0ed588d744e0a027de478fabdb053809c63ea7cf064287aaf249f5138
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:cc4a3d9e130f443ccb8e15884c47ec2938f06f0e9849c434f1b48000300d0a31
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:ef2e0bf85965850ab63cf759ebe65d82b332273e35c5cd1a11c879dbfd5530d6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:fdbbd963cc608c0b518f4d7681e66b147721529eca3666e2d3798ac3c573b955
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:5851e876ff1ee250af52a891fcf5023fb84d947709a3578974a91ca40c325ded
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:96e8b81e83b103eb318f655bbcd788056ea3360d0dd59763ae12e59cd5aebf14
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:4631a885ce5ec70560ceda3e8f1446008acf95ab6c4d4cc4fdd7e9e329055a54
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:f0624bc66fdaa071f0fde961f0991e0f1a4fcd7d9ce19f40bba0bc18eaa9526c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:b3db96a0397ce81f44db63fa2665bbf0f02936ce5524083036c6fb25fd1f3076
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:6804d0c1a3e2d836dfbb87edf917852cd9466ce4c8b0a3a3009c9f1dd174c8a7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:4eb99dbd0b3dabdc38a763dbb385368048867ba4682660119864ced75563c34a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:5ff3e77c017da8a29bbfb6397577ecdfe19ac11fc88801ddd718520d0b39fdef