Sign inSign up
Google Cloud CLI

dhi.io/cloud-sdk

Google Cloud CLI 585.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

585-debian-fips, 585-debian13-fips, 585-fips, 585.0-debian-fips, 585.0-debian13-fips, 585.0-fips, 585.0.0-debian-fips, 585.0.0-debian13-fips, 585.0.0-fips

Index digest:

sha256:236e11dd847c1c27a2fc11ea7eac9e4e0fc9ac0a2d253e30c04a6de8e8969e8a

Manifest digest:

sha256:83eac349f8526bb3575c63fd29d65fa2153f4491be79e2034c0dbd3bb9e5bedd

Size

81.75 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
1
10
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cloud-sdk:585-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cloud-sdk:585-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cloud-sdk@sha256:17f2235bee5a65a7382b36c22857f83910e70d407cc8e1e195f7c3e1ca6d0c25
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cloud-sdk@sha256:75b044565901dafa539063355ad81653c84627ea5e623865396ae1472572998e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cloud-sdk@sha256:968b5655d6645d9e19356257120c33388a9025ec625e0c26e0923c92954b939f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cloud-sdk@sha256:3b2c5c88abbf8b9974d08781eeb6c9bf074e0bf093071ad130a051bb7e8587a7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cloud-sdk@sha256:21c8ad6a32ab7756003f3853c8b317ce9c00e93157f7ec94d61deba2f1e74f95
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cloud-sdk@sha256:6a47abd02ac8d4f8ff5dfd5b55c89cf681a607111584fbd459c9c1aaf09aeb90
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cloud-sdk@sha256:e3d78666ec708df02ec4e8047cc21dc9647976932a2c589d4ad34d706bb1eec8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cloud-sdk@sha256:eebb6dbf1f1ab575766b16419fad1d0e40f50e0ab2645d54db279c7fe7211d4c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cloud-sdk@sha256:f61dd7fb7571a2b195fdea2157cf470015d451bf1cbb027b60407e5138749271
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cloud-sdk@sha256:3fbdbe24823cfa7d04039a1e512484e6c48eed0c223e391a40ab8fce25f8973f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cloud-sdk@sha256:7cd217291b7bd3e0a80680fc86752f6b8aa8519d474702c5f7b7f3ff676b1b32
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cloud-sdk@sha256:97b647265d8b3668ad749910d96e7775b3234e6ba15823bcfeb0387b2e70b0c7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cloud-sdk@sha256:ae2825a7bf5f23fc76b38a67fb328a72c320d3f11934c9055401723238bc7b2b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cloud-sdk@sha256:098f1fd84434b7aa895b4a2e12369ac1bf29358e8e9d1e5d210cba4e984f364b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cloud-sdk@sha256:a51667ac61901fc2f1b86e93ff6ed6c7273e8544b054c1cf95f58ecf3b4ca577
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cloud-sdk@sha256:801610f4d4a045cc463df96bb7f0a9c4bdf59a5f36639024f74e04c0f8926f0c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cloud-sdk@sha256:17cfcb0fc91dace565b1aa0ccc9bbfbbd16e5bfd7d263efac6419daf565e02a4