Sign inSign up
Go (golang)

dhi.io/golang

Go 1.26.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

1.26-alpine-dev, 1.26-alpine3.24-dev, 1.26.8-alpine-dev, 1.26.8-alpine3.24-dev

Index digest:

sha256:5d92bb1c84c3445be65f3c7748a1365f298e5468d206d70f9a305b25900a2aa8

Manifest digest:

sha256:d2c87c1632c7f32c4cb4801f88ed5a830e69acb7f9abbca5a5f6894fc3e2c213

Size

121.86 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/golang:1.26-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/golang:1.26-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/golang@sha256:0a25145e744ce3a6533590464adaa2ce271f1196b64e4685bae58ef0b6119648
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/golang@sha256:ea7a3299bcaa710ede5562d1e0ae5426e421872737f0cc9504795b650872b76b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/golang@sha256:ebe7981c1efb4568b062746370e22f9065d5328f5fa79dce8b3c5b09adaca594
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/golang@sha256:f757a756c2c7ea82682398280655f6942e5d6e84ef066cefad56cf65dfdd71bc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/golang@sha256:3bf70d05e525742e52fb92963770d957f366f76c59521ee316685ee68be56ad0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/golang@sha256:67cdb35dd0fbdb5ca4337f30cf197e053ec5176ed6620979cb879f8ff5b01f1f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/golang@sha256:82f86e0da48ec8f16cc011545194e429fa768cacb79ef6f9ac6d11a1f2838025
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/golang@sha256:95848dd19d3d7b9cb8248ad88197ea2546753c3afe43ddcfc3dc8e7466870359
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/golang@sha256:7d5cc14fd6b0f35c130799cceda68f0efb3e811001f2ec8325e79b48c7d70f7a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/golang@sha256:a1e2cb307945aad729e03b47459ba01090e1019e44e6ac6888ffba0826756651
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/golang@sha256:d7ab0fa881ba2fd9020a19de3bb608e35ec95f1ce86742671df48ad16fbffe98
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/golang@sha256:13ab586dbaf79675a14ffa8e18bfce39e1de320f18e47f9724cd4e09b7dda673
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/golang@sha256:b39daad0198f9ec5aba7bc9535cc82b6f090c323ee1adc3a3e1d3b28a0e4d8a1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/golang@sha256:8d38ad11f3dbd6473d01191f70bc95a06a91c17dd83ecdcac97b714990244d56