Sign inSign up
Go (golang)

dhi.io/golang

Go 1.26.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1.26-alpine3.23-fips-dev, 1.26.8-alpine3.23-fips-dev

Index digest:

sha256:9e2c93b2d5168e17d281c14e5b2972ecbf4c708d7eb4a804ac84740f92d4a28c

Manifest digest:

sha256:441e1912d98358105a33690b0f1052134a4799f7a33bdc4b026da866b02c8bb9

Size

122.99 MB

Last pushed

4 days ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/golang:1.26-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/golang:1.26-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/golang@sha256:b96b61071569767c111d19dcc60a67279265fdd315f7250a092bdc6575d67ca0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/golang@sha256:f4c3d6fc04cf4993f1db9739949e947b10d286469a375042b2228b9db0c6109a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/golang@sha256:e30956a1e22c6e0d3cf035f812f641ea1e03d885f298dae4bd6d1826e1d6d124
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/golang@sha256:778a722a5ed5565c8c29c63ed89db314194c2ae6a8be33a1162ee59fbb59aed4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/golang@sha256:673a0c5597b0fc11636eaf421aed0f38f869535943d6c2c3415c338b3ce67177
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/golang@sha256:7dce2a9a0de6bf1f3805e1a620d7511a7253a6a559f534260dd69419ac57e692
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/golang@sha256:b3c142cc349625aad8e126d33e9b00aaa40fbf5462ec98865c79b9915fd6a1b0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/golang@sha256:6b1846798528f9b22242479d8d8b0ba4f508c10095d30b80b7bd5f491aff4b4e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/golang@sha256:43da45101e3bbdfd8d20de07db7ff613204d6d0b791ca84b08f0868745ba1a52
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/golang@sha256:609f2aef96625a09aa442f4ee9741a1fd0d2287cd42982b5ac859d7e663ccc08
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/golang@sha256:47871eb04e1043b231b3e979cfb7330239a36fa21d1977f55eb93a5645c5d08d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/golang@sha256:d3d512904f940b902a870543a15b8a76d97565fbdab9ec5ddced22e5b16ea8cf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/golang@sha256:b7e576c644e66e2118263b2f9858c3243a16a1ec9d5056e221b077460c404cec
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/golang@sha256:dea9bb206ab47c789c6f503e2718f769f063f116b237b2418f17ab3f92a376d0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/golang@sha256:7682ca83e71d6fa9b2408ef9a8cae2ba12147545c40ac777efb196d2087abe58
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/golang@sha256:ac5565bb9cc9137a04942a92d9e21a9f2bdd9bef5f715be278fbe20983618c4e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/golang@sha256:a68701dcf7f2f6f8fcdaa5ce2752f2deb3624e6ea5a810a1dfa37c40ece402c1