Sign inSign up
Go (golang)

dhi.io/golang

Go 1.26.x (msft, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.26-debian-msft-fips-dev, 1.26-debian13-msft-fips-dev, 1.26-msft-fips-dev, 1.26.8-debian-msft-fips-dev, 1.26.8-debian13-msft-fips-dev, 1.26.8-msft-fips-dev

Index digest:

sha256:c6f2fe66e5cfd9b2122670121363961cc82985b1a60cc509c81164221677fb0b

Manifest digest:

sha256:32b878bb2eeb5f21b7837c40a543e7e3704aeced48d41f76e0c8b199f1da32a9

Size

174.23 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/golang:1.26-debian-msft-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/golang:1.26-debian-msft-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/golang@sha256:158044d964ce338a38aff7f00e1b7d54d74374b48bd323eaeb3861ccc2d38582
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/golang@sha256:3fa0e071bf02410680eac34640987b9c6787b77701c8ddc2f2bd7332680ca219
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/golang@sha256:570b343115a88642314cd5cf1eb9b335b615bc70f845f2b4e929ab53c13bf6c9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/golang@sha256:41210bb80e946d55d04d75339f1e1b44fb509b4415fefd12bf2146a6e8a19415
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/golang@sha256:14cb93258ab3695b85813062b80502987be9082dad40198f66045b7e36ae0e95
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/golang@sha256:e59965d2ad2e653d153f76a1cfcba680fccb1b0968960670f2f122a398800fe3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/golang@sha256:f540ee8c930b1940470e0dc1633e9fe410130785649feccea5d67c4a566e715f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/golang@sha256:f79140264fa8659d856479ab698b63a32c97b7fa57af8879972bc24104e9b2d3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/golang@sha256:089f843e0f0eabda35b5f700f5222190d33d072caeeff381b1c5d13b143d0f7a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/golang@sha256:647e636fe75429cea27e60317f9e6116fe75f90902e215862cf8e01a6e580401
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/golang@sha256:6802d228e6adedf9458999fe9787d49033fbcdd91bb4483a57d59c9c6a4044b2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/golang@sha256:18e190adae8b0edf4cdc868fe8273239d5e43c14fc9e2b6b5990e5d95f320a17
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/golang@sha256:497c94b40e4ef4ec57b2602fb66b363ea2b339b6d0aea4706bbc765cb7080946
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/golang@sha256:865d3fcaca6182b589bbc7b5955e5e7943afcde3ea03a6e8a9078e0e9df2cf0d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/golang@sha256:4d8210eb42cb0aa4099248f4a63a225ffa5856e8db42d64a56d19276aeb59250
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/golang@sha256:f0a69d6d294e3eefbaf5b01d4a274b64139da23ad5be5c8920f51ba60f840466
SPDX SBOMhttps://spdx.dev/Documentdhi.io/golang@sha256:ace561c4ea5bfead3bde135e59df728d0ca2a46c2f62f952bad5ac9734be0908