Sign inSign up
Go (golang)

dhi.io/golang

Go 1.26.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1.26-alpine-fips-dev, 1.26-alpine3.24-fips-dev, 1.26.9-alpine-fips-dev, 1.26.9-alpine3.24-fips-dev

Index digest:

sha256:1853570d4a79711b314998aed8034000427e81599912fe88781fb8eafcf8cf02

Manifest digest:

sha256:9d781fa5a2ee54b41aa74bcce4b248c042876a3b2a52162c530b9a6587384ebc

Size

122.92 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/golang:1.26-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/golang:1.26-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/golang@sha256:19fe6466c30572dac895c4c29458b191b3a5d599c2cd13fb2cd9487cd9ad7328
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/golang@sha256:79ac3603d59f835df1d26af813adeb5f954b90ab48831a482b093b117d9a2d3f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/golang@sha256:e0a870730e83efb4a3d89138ac2e9b840625b192c54151c8d74074d8e8d1e489
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/golang@sha256:d55daa72b0bcf249af51ab05c61c7b749181c781b214e542db315055425c3bfc
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/golang@sha256:0c95b6a22c8f6f5614c8b1f6f79a8861a1ac03d209a333098274a0e6ecb50f6a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/golang@sha256:b31f7d5d4c560a8f1d5679c3eb2cd6c15dac6ba2f877b9e1db7cc21f84e9f1e2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/golang@sha256:efba6e1330f9e6e4a6c46a2bd0c37c7949e00cc55f1dda081fad816ebe66a587
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/golang@sha256:6352cb63276952379a65d24d69616f8c3ec6cb95999158a018dcc287c7ca739e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/golang@sha256:c2d566f228881dd8375665f31a33471fa17e8a674465806725a12dc123c28593
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/golang@sha256:e42cf15b74330b6b466fbad2c807558196bd15a495ae0a27d90ef07f66770b35
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/golang@sha256:9b2cd8fd7d7cb1d5b84cff7ac3c9bdd477c16d7d61f354a15c0d15620acb2a9e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/golang@sha256:1ce4f29a01ecb6917cccc5339c68500dffbdec3166536ecf8c7845ffe0cc0674
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/golang@sha256:6f908d2fae5ecc72d627082acc92ca6d67201e258b5dd6a480eeb71d8456edc1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/golang@sha256:2e18a2689f052b4c831b0279faeaeb39ac8993ca89cce891dcc912d7d2c02a30
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/golang@sha256:5295a43e6528e268f550fa10ade28a5d4062f30c4ec82e2a6e94410e360dfaef
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/golang@sha256:014fca750e5c91e27c8618382d8646179eec67cf175e00e2d10294fb6157924d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/golang@sha256:b744ee91b0e68a279bff22cc74734ad11fe0a55f0a2627743258d43371464675