Sign inSign up
Go (golang)

dhi.io/golang

Go 1.26.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1.26-alpine-fips, 1.26-alpine3.24-fips, 1.26.8-alpine-fips, 1.26.8-alpine3.24-fips

Index digest:

sha256:adb2037a3d3daa1a6e0643cffe25ce740ea7d1b733bc88cbae32d25310699227

Manifest digest:

sha256:09330b9c8fea463706b71b9eb9b89c69bf6196280102d1f10361a7d91603e42e

Size

100.16 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/golang:1.26-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/golang:1.26-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/golang@sha256:4dfb84291d6aaa2a48f507d3c980d84b34c82cf1490f3674fa7ab1c4a2daf50c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/golang@sha256:43ac1239caa57753f0027e356dffb80935bb3916e682b738566ed6d8a6326dfc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/golang@sha256:5debd9f3394d835e4a646a4eaa21ca051882cd49be86c0cd25a7c09554389f32
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/golang@sha256:2bae5f2759a9f8cb1a35bba4db694bbb0e8bf2361147597cb8b33e59e0a5a7d9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/golang@sha256:f5ed4e39a8d1fa734ceae539225f1f2c2debff3a6649878a61344a68ea9ddfd0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/golang@sha256:be9607c638d87ecf55c9c89d9d51894b15e65e65624cfcfd2a7a100c3f21bcaf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/golang@sha256:f33d3c60c5ce97d934d68c6f76c33a9f9277552e3bd9104c4527fc2c36274c65
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/golang@sha256:6efcdf14e80aa13eeec260fd5010c891b5dff972ff96c8936d07049dd1cdf397
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/golang@sha256:f6bf894f8a0a45ba94fad8b6ee0f81844f7f4384bc0e6bd92b46d348a470f9f3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/golang@sha256:312e26f39ca26976d9abc73bf444c649c91a5184f48ae4f78467f25cdde0f1be
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/golang@sha256:4f9faef9885956842704b2b50a243ae7892f353e58fdfaeb73042ba49e3ecbc7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/golang@sha256:9bf6324915998e63c16331d76f18c2a49ce3c78f158a2c29a60396babb3ec400
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/golang@sha256:9f77d876632fb615c85737d265c0423a2de9249f4b21eaf346db1af6c3c9f443
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/golang@sha256:eaa1d420efbb7cfc44a3fe09f8ade8190b9885cb20cea79c30a5dad7439e0d0d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/golang@sha256:d27a0ecbd8ab377a3bc5c4ca067e4b9e93284dffc53518db7547a7bb2aadddb4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/golang@sha256:6f335b8d2837a2b386f5f381366d13a8c15be28a9cbe01c0ed3635fbd99d5527