Sign inSign up
Go (golang)

dhi.io/golang

Go 1.27.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-fips-dev, 1.27-alpine3.23-fips-dev, 1.27.2-alpine3.23-fips-dev

Index digest:

sha256:565993398a2b0bbf4b7f541af96ef8f1f56e673cd4380fbd61cb79d8f9166b43

Manifest digest:

sha256:87f78875422615bbd338080d36dead6ed41cc8aa8a601161eb715fb37fdece46

Size

126.16 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/golang:1-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/golang:1-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/golang@sha256:08467c450eaf5a4e49a2cb03ac3d218bbc311fc2a0e96a988b2757ae891b6fc9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/golang@sha256:b83a948fea3101a813fcff2457207f3eb5c671f96d21c48d4ce9e4af4316b116
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/golang@sha256:62695eacb7ee4121c548d821e7c76d65a3b01fbc42a280a62b24f82ecbc523c6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/golang@sha256:bc4dc3255f9b865309c64d02b3cf2f49c93cf9fd750a89f628fb05a780141c46
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/golang@sha256:7788e1c75cd572185525cdc9e2ca20fda56c1c975f6246d00ffbfcb2ce018837
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/golang@sha256:576198be3ee7137fc940e9bfb8fe768fe23b208adb93fe1d837121be7fae7081
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/golang@sha256:94a52ad0ea97732b5804d2bd71f178800048f688546cfbb4da02e550c3bc421f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/golang@sha256:658c8c76a5a71681576bf6b7eddd1f80c9fed8add7bdba6c658efee4765d8ff3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/golang@sha256:54030e2769849a842fed2eb0ab0cd307e01b7daa5aca00d79e00534c8e2aaebe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/golang@sha256:3ecacc69d3d700bfe5911df7677328d7b43ef4c00c797e77883ad7ffd1bc187f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/golang@sha256:7542801f2b4359379ea9408956105d628dc85eff74a6c9dbb860cfb889017aae
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/golang@sha256:299fe29594b6cc1835101edc7b7d3d1e3d36f239c62a6c40fbc23f0bd4504599
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/golang@sha256:b592abe0f3e4d6ddffcd7fce2605d2b94286886a41e1ca484e6d95cd1236700e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/golang@sha256:6f275ba4ce2679f06d86becf4d21854e294b0e66a23d85f5cf3b23f91fa45e00
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/golang@sha256:0a0805931aba66bd06d2db44070e0edb47d05a6fdad797b73e99d1fdeb618647
SPDX SBOMhttps://spdx.dev/Documentdhi.io/golang@sha256:5d31d02fc87bc04970880f4440a93246c12fc02f6851fd0cc7a01340d6384b22