Sign inSign up
Go (golang)

dhi.io/golang

Go 1.26.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1.26-alpine3.23-fips-dev, 1.26.9-alpine3.23-fips-dev

Index digest:

sha256:8a1da7d36c3faf17df2741f1e4681cf163a5250239d6460a63b7cae78584da48

Manifest digest:

sha256:ae94128b5529937d85be94461e6ddd4e9aebd54c4bb7077898b05b8d959284c1

Size

122.97 MB

Last pushed

24 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/golang:1.26-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/golang:1.26-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/golang@sha256:4c43c4e20f13c30eed74a6d053b29ff7969dc1bcc2566d7c441886b9cca485e6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/golang@sha256:4d46b93055d56a74a8ca4980958f1fd47343e2041d4976fff064ee0c88b1ea05
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/golang@sha256:0c9412d08449782027d739b32ffc2233c3324eb18d7f754066de4e0267f179d3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/golang@sha256:352085acd5666b69d474a9d3330e2d8aa11337a4b541a2a91741f88feb30431f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/golang@sha256:920b895def12e8698541e9d607e90cf5d2a1506beb3f1a115ec1fd746ab04a13
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/golang@sha256:7d286b1524d7d31a9865ce3b6bb175d43eaccb4786a952a4016b322442d4875f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/golang@sha256:85ae104e7f28580f15a7f1b73ae36742bcfaa8b451be0dce45a4a128c3aafa32
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/golang@sha256:e690a8a13f3c5c03bb4b2307e8cf8c9e7b9c1ebf9b7c9ec363326449610fc8b5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/golang@sha256:dfbf5f8a6a5f371c3d4a1c277604e890665984573fc2ad2b044c9aa0b0848d32
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/golang@sha256:4f98c43b8cc8d04927254e8e3286e15c7e86ac53b04d92e845ebb026086f6b1a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/golang@sha256:33ae2508b84263d1102eb30677d18b3611c7f679aeae514be4916897a71ffc83
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/golang@sha256:b13a52bce621cf2d5267312a9f58c3c7fdc9ddd48e329fa8be72293c9201ff31
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/golang@sha256:6d6d6278f105a8920d33eb538dc56edfbde0cfacac8f52ab284189d0757b11b1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/golang@sha256:e3e846b0781df601986061d22581b40470a80b983506f031ef72fad5fb64390b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/golang@sha256:a00ae169340e0001b3301eeeb32088e42f1316f81482d45a7a50818f6f266dcc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/golang@sha256:b686f3a61ac0f825f72a15ac82b6ff0db5c3802180707ec4022947f2a3035bc8