Sign inSign up
Go (golang)

dhi.io/golang

Go 1.27.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-dev, 1.27-alpine3.23-dev, 1.27.1-alpine3.23-dev

Index digest:

sha256:0d95d4f9889abcf60c182228d28fa83fde3e0dc2330bb1365e5960273b43ed57

Manifest digest:

sha256:ec9394280de120e2c2588bdfa936b5919f01be26850243660f2d11ae7974ce8e

Size

124.86 MB

Last pushed

6 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/golang:1-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/golang:1-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/golang@sha256:c411e3a6937506b622efbafbb0f8c1ea18e8b72034f78e43fd150a87264647b1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/golang@sha256:5f473975fa6708e4abd8258737c54bbcdfd6865473af3312c40bfc0c0981d83e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/golang@sha256:7e2910eef2c06e44cef19ebc5454a8031523e0b2173906f778e019c3249c2ff5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/golang@sha256:32f81189de2d4a53719d8c8fd997d9e8ca778f3a0d24b49a63dc5a0683f034ef
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/golang@sha256:e63cbbb35563f205059ce9177bab12e8972d39408e345a04f9b806a07d662db5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/golang@sha256:a73198bcd24135c957fcd95a2b6b13051e09f660df3b3362f64b15a146f5fdcb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/golang@sha256:62ec235f7228f210786cba7127926e39f9559c92f137ffd59e18229506f4decd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/golang@sha256:ef4453acdfe7cc656cabe366bd28b0e1ae3118a5cbefc8344dbcc3cc437d4171
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/golang@sha256:b01b4e1ce0969f3eb82dfa25c20db0c65ee08bd933bcc0d50d4504da4e7ca1b2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/golang@sha256:edb6033a221a42f5bedfe4c7dbc5fda9e5e8ae989580d5c95d11b1182b113fd3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/golang@sha256:c94312cc169d081808ca26f6d8771d45111b08c65ca121d05f3480a918d1074b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/golang@sha256:ef834867ee1f3bf4282879e9d8c2a163e2acbe334bd16a6438a2a782cc407ecf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/golang@sha256:2d364a2e10ff72efcc0b43f2e44c1c66c6844899654ed4ed66201170975da776
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/golang@sha256:42aeae539b4ab360d9d92db82e1831cb0bac3a7fda4b1581a396f38b4abb5fd1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/golang@sha256:85510bd5fdf03724d9637e40808bf552d43097ebdf2434522e713c26e949cb25