Sign inSign up
Go (golang)

dhi.io/golang

Go 1.27.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-fips-dev, 1.27-alpine3.23-fips-dev, 1.27.1-alpine3.23-fips-dev

Index digest:

sha256:9c7d40a26e41fc74394aa057756e1ea596fd6a61a151266b3ec1904524849071

Manifest digest:

sha256:672ae582bc02164a531081fbebeeea90de61d0bd3256d7384023bdac73474827

Size

126.09 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/golang:1-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/golang:1-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/golang@sha256:b5f073dd587b5d92cad10fae94e6947da3b2b2fc8f1a8bb449a92b99b486ee43
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/golang@sha256:f80ed7070719a8a33f771b090b9dcb90dc902e0c5cc66b50f6df34ce23a0fbbb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/golang@sha256:84c98600ea2b7b598d4d7278f0dabe972e9a67a8a3b5965eed978a8049fd46e6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/golang@sha256:07452bf825114e0cc14216ec6333bd1014ead3ee712e698f414e350544d37fe5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/golang@sha256:b9ee9f99501474e3554249324f95789c71b496c9f1a53270d208056b44f7129d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/golang@sha256:a0a03fabacd58b2377b95510c86685ff968d357c96c76f9ce4256aa0490e2041
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/golang@sha256:fe8329c1794d386dc6101e32789a40880b656424637172e6b6ec728cf458e826
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/golang@sha256:409e0263b06d04a4d386bb601ce069bcdde71987e87b2fbd7f6083ea36b4127e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/golang@sha256:87136f7312b28c289c5da3d01112e22a1336f0fbae6e452f067b71bbe88e38df
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/golang@sha256:56c7c8950436043d6e687e12bec54a39f1c1a07d782090d008bf3ad92ff9f134
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/golang@sha256:99abe0fbfe58c8f56c1452d4caae0dc5b272a7ab8d2c5b6888551a0404c64cfa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/golang@sha256:3379a4ddc1a219bbe8a384a0abe71c57fa09fde41fb22b01497b44cf4e28c87d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/golang@sha256:34614518acb1ea58dbfb3d6a5c6aa0630379b354fbe54a2511389886f8d49f6c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/golang@sha256:048d6bb999e0e7281d38ae55baf9256f270739971c09997d0dcece3a83c18e8a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/golang@sha256:c09e8922ed8f863d48c0f758cf2f510d0c64bf54d953cb92b3dc0b736797e512
SPDX SBOMhttps://spdx.dev/Documentdhi.io/golang@sha256:50bb90a6608d6349b6bfc9b70796fdbda534945bde2ebdf8ecf44923e1c9bc53