Sign inSign up
Go (golang)

dhi.io/golang

Go 1.26.x (msft, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.26-debian-msft-fips-dev, 1.26-debian13-msft-fips-dev, 1.26-msft-fips-dev, 1.26.8-debian-msft-fips-dev, 1.26.8-debian13-msft-fips-dev, 1.26.8-msft-fips-dev

Index digest:

sha256:5d7ad79bef6d31ce2df946aa45d0a1f3862d4e3d41bd5a15a69ebcdb6063190a

Manifest digest:

sha256:3260045dc6cb532726904fa914a2ba59cd08804ceb7aeaa6ce691f45e8d25c69

Size

174.21 MB

Last pushed

15 hours ago

Vulnerabilities

4
12
0
2
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/golang:1.26-debian-msft-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/golang:1.26-debian-msft-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/golang@sha256:f822ec07d655a17131c6f8907393fc723bb35ec456af0e56a7533afba2bcb9dc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/golang@sha256:8e3d350ee091e6ec1c7acf5015fee141740a0f1d87b08f33a2509985d050d894
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/golang@sha256:d37d938accfb67d694862708694f579f7854d1f2e6b97d69b0e2d2a54d828e03
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/golang@sha256:e3d65a4a0c720b498b8451b114255916f16f4092ec696b060d40eaf3d5875ac7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/golang@sha256:45170425ce66033d3366b054d29719073f5371d76cfc629d0cb16e0552f6dd78
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/golang@sha256:cf7d5b45630cccf812c5d725ee7ed9203fc7c2c65da3331df023498039989f94
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/golang@sha256:dfc7a5bc0004b91c69ae87d189f645e25ce5feefda71b679b36f2c50ae9c26ef
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/golang@sha256:bb8471e602e139212c46d5a613d56393d7b96511b9ce673c4f2c065695c238fb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/golang@sha256:2ac40b2a930680fe43b59d88394d728c3cf80c6f078a3202bc6760bdc44d5b44
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/golang@sha256:b661bc6d63613f844e3d61693ddcd49f0ec089620eaa4c5713a7f258c95b9aec
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/golang@sha256:114c04157ad7f7081ad19f82aa1a29aea202d724bb997fcb1f69f74324533615
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/golang@sha256:12ba51ecb21c9a15fbe105fca4f58c7e3457c80acdb68d72b23004cf2cadfaf8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/golang@sha256:2cb597c0f15a4bbbca2a15006c1037833a8e428e55889716fd179f73a32d100d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/golang@sha256:196ec7ded6873689b2ae175eb56395accf6beecff109745e56bec32176a9b7d9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/golang@sha256:d4970b512f628130ae3bd77513c978f8c168af8776a81f4c45df80177105bd55
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/golang@sha256:743edd29819adf9c3067edee518b9c1998e9a13c8cca1c1fe19bee63dabd0a3f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/golang@sha256:2151d6a97742ebe0f81204fd9980e0d5cd12b32f7eab6e28d4a62a30353199e7