Sign inSign up
Go (golang)

dhi.io/golang

Go 1.27.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.27-alpine-fips-dev, 1.27-alpine3.24-fips-dev, 1.27.1-alpine-fips-dev, 1.27.1-alpine3.24-fips-dev

Index digest:

sha256:fb401112ab44296913dc410c9c4bec5f4ca91667cb1daa970dfe1fd7d1275763

Manifest digest:

sha256:4508107ac2bb35f78cc906c0a524da5ae97a6e6297c417003a32652555805c3e

Size

126.06 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/golang:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/golang:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/golang@sha256:f09b36c99eca3598cdaf0899b0eaff34287adcd28661e26f2e27be99d6610182
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/golang@sha256:e64bdd3e08698a4ee4e2a2cdd3f967638206ab578836f7202f780fc3fa7c64b7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/golang@sha256:cb1e4d0691553fba850e370de6b1d064c888c54a1a7e2dbe8dadd8e1376fc1e9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/golang@sha256:6f3710266233f7018c55be6aa29316f2943e266b8b5dbecf601e782a1903bad4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/golang@sha256:4dbcb8fe2f3dd120dc411976f73cae4d22387e04f4f4b7dd15c96461205ba2e1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/golang@sha256:6e7f333557c8b5d028fb7dfbb28e4bfa9107aceb1cd4c6be40d813071f9548e2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/golang@sha256:e88070c7d0458c52ad0d3c652e68d5613562ddb243bb4b8d1e84b43776cdabb7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/golang@sha256:6b00f5067c69f895cd0c437ff6d78d114821de2c0945c60cc2a530b4cf085cca
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/golang@sha256:b3fbf61dbe7f85db99deb55aaed04f3e3489bcabadbb52ac92a80139ccd440a3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/golang@sha256:5ee7957e48ec08436b04c9579855a7fee684d958c3249823348805905bde56e9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/golang@sha256:cb16dd4cbfb8f0452bd1e294a40d8d4fbe4cd39bcabda1859b11de5406be57bf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/golang@sha256:3091edab0ae5c878f2520f06358ac21be243441b46eae50434e18aec85cb77d1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/golang@sha256:8c008f7d537a82fee1c68f13ce1c8ffc3640dfc529886b8b12090a9209657ff4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/golang@sha256:023827aee6820f52aaad6bb14e7a6b6e2d028e9e60da544f1b37ddf3b690fe67
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/golang@sha256:b804bb1703e70145e8edc5cc05a294eb7c1893aea1f741a16b3be5bc0c479da0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/golang@sha256:0ed62d68ae64f120083a911469f86b45b9ccfd019fcd84b72b9c760b0da54af1