Sign inSign up
Go (golang)

dhi.io/golang

Go 1.27.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.27-alpine-fips-dev, 1.27-alpine3.24-fips-dev, 1.27.1-alpine-fips-dev, 1.27.1-alpine3.24-fips-dev

Index digest:

sha256:4dda04e78d37682390972f40bec50a72b2d62c9c3efec2b1cc5527494850a26d

Manifest digest:

sha256:43161efe3f0346918bb3bb84b6f51256de56bfc03ace757779ada6fafd9a2d84

Size

126.11 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/golang:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/golang:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/golang@sha256:9fbcdfb80a26c08884111f5b3760f4eef6005e1d574c337db2bc2e018fe76589
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/golang@sha256:89bb95aa3f8ba7f208e12a1972a307866bb7bef858e7e74f1e3cbbad363f8c00
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/golang@sha256:2b2e24b2a1f32569a3ab281aa8c3ee410c6597dc76dc539e6e8bfe61f6231869
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/golang@sha256:373f57d0dc50bd965d83f110188edbfc99baf25d7a3b7a3aa22bcbf6977b538e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/golang@sha256:e51d507ad19e86c45a5565bd0d2ea59609302b53dec2933c7b484443efe15a74
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/golang@sha256:a4bbc5d4e7e6401945a615d2572e035ab8b17bfa96c4a33c067a755f27532583
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/golang@sha256:8ede49a9bfefff3059792ac0ff1293ee02c8bd5ec4d346aea8407fdb84302620
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/golang@sha256:6d08e2823ccdac2be7bd505486d0da2ae7a1ff516b09537d5f8a85f58970bfe4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/golang@sha256:8a3165dbc6be7022fb1a2797cf23544b44aa91f1719465d964477e79564676d2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/golang@sha256:03fa2829b520988d1f6c1431284f243cb17e42584c468461b8e14378adc40ada
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/golang@sha256:cb6066f6ecf7145c2f9dc269c6a74d1d8eb776d1a4a9c9256d4290a8893969c6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/golang@sha256:e8e3e0656ea9aba897ef04ed91ddec1806e41ec37b3d44b4f8661fead309040e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/golang@sha256:b807834edfe2e8228ac4536f9ea62da38d0a08699050f67c1582132d90765992
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/golang@sha256:c90a1302cbd2df71bfab82037febe3fae6fba65444d29c4f3c1b59b69cdb90b6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/golang@sha256:f118fc3005b236aa8cf99f9c8321d746a1636b280f8c79d696f5e2ab26ccd6f5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/golang@sha256:9c17dadbb93bf931ee96db705c9b90aa39f03ff95cba1c245608ddfe74976ecb