Sign inSign up
Go (golang)

dhi.io/golang

Go 1.26.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1.26-alpine-fips-dev, 1.26-alpine3.24-fips-dev, 1.26.8-alpine-fips-dev, 1.26.8-alpine3.24-fips-dev

Index digest:

sha256:baa1aaf9cce752123a12b07114ea9238f94e855e11dd253849d3ad722ef827f9

Manifest digest:

sha256:f363e9276c4eec33057e25e8e25db19d5b3b606b9b6e7b80b9cffe4ef6a6d22b

Size

123.02 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/golang:1.26-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/golang:1.26-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/golang@sha256:1ba66933efccf94cfba8783080389c0d6c6c9467a435c2c4978317cf971016c3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/golang@sha256:c747e5d7743292483d686f8436123871d92cf0d3eceb683842e90e9cf3c5fb60
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/golang@sha256:8ddd6104c0ba11ee864e769f8f59abcca788be2b2f35a1f497bc88837143c75c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/golang@sha256:ddcd21e1f2c0b8bbaa2cd190bed1a9244547d9b030bb03f3226404e0fd2ca9d0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/golang@sha256:7247a0b200a38f79e46150bc3702d76f7e4b10ed3059d38792986a2770bd0811
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/golang@sha256:1e3cfd02ea6b239d6b78e33c4f5b2c2f03f914231bca0640674dd9fabc4886a0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/golang@sha256:28d59f0638ce09b759d9a75aef245787a5e7ab4c39aa540d45fcb4c8356b078b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/golang@sha256:15ec2a85d9e6825f0a73371b3f83d717a4a9d754a08b98af392490df99c6152b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/golang@sha256:f1297a78ae08784764d6c7fc99e66c80008c19223c59ada176c7bc92acadebc8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/golang@sha256:50ef784d03f4718d223766d9310bc65a0191dbed60482c1892b92604b8c6a3f6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/golang@sha256:497bf9d2947b67e67899e1528f8e6f2710222fe117482a5cb3c4214b5775943b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/golang@sha256:cc123b712661b2b49ac1dfecabb92e39abd6dda4bfdf1ad9d46aa61fefc6ad6a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/golang@sha256:37a1ee874bb07aee80720f6587fbc359e76f48c490e073120c84bf0af166ed5a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/golang@sha256:56f9ad19112e2e753101e60ad51b24bb7a84bb0d0c234ad6530626cd0ebbebef
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/golang@sha256:b6bba0698b506da244329dcb238e25da40ca2b946940c7ea8c1314d5f1761054
SPDX SBOMhttps://spdx.dev/Documentdhi.io/golang@sha256:0f4bb2eaf521be55d7080fa283874a7549081317a5e85b6e3eb4ae448c17b4cc