Sign inSign up
Go (golang)

dhi.io/golang

Go 1.26.x (msft, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.26-debian-msft-fips-dev, 1.26-debian13-msft-fips-dev, 1.26-msft-fips-dev, 1.26.8-debian-msft-fips-dev, 1.26.8-debian13-msft-fips-dev, 1.26.8-msft-fips-dev

Index digest:

sha256:c7301bbd9a7afe581bd5eeb0456918174bc455b1614480751f0173a6e8546cc6

Manifest digest:

sha256:b9268c8b7100903412aa2854c374e7d3f39c5969e0c19042d195786b0e3b85d8

Size

174.22 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/golang:1.26-debian-msft-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/golang:1.26-debian-msft-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/golang@sha256:2e9f53b43b10c196e2395807edfed376121dec2c8c1a846efac219c37511aa15
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/golang@sha256:2eb2f447a68f70156c8c0443c474f24241d2709e0f9634dd5dcf8e52ec8d3e55
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/golang@sha256:7013258072ea8e7ac44d5601c5ad95e2f4817b22c31e461276c332332524c79c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/golang@sha256:7ce536a7863024463b93057ceaafcf0296cd97a6fd8f980853c29b4335cce7b0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/golang@sha256:c1f007fcac355da1f7eb4701388b201a2df9d54f3e1e86da3f9b0fb687f0ba0b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/golang@sha256:3ad4a850582d615b936a40d83783d176186f590df5e07aa5b33bb4745db09d4b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/golang@sha256:f2d7a1331290c77df13e5b72a9e98dc9bf7b8e69f9d56e537293e8911bb5fe08
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/golang@sha256:75ed123df5a9bb68d00ea60e4dede60a06c7b8dc5b4cf043e73bdeb5a8b378d5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/golang@sha256:1396238ee87adba3d574be49e810189828c310798731d75f8600f2d4fc9c5587
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/golang@sha256:50d5890c724c99e22345da71a187cd0a05e468905b79f6ef39091e9851270133
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/golang@sha256:04193bae2cef60f8a593d9856bf95faddb3523a06906da814a5203b41f0cf452
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/golang@sha256:c678ee186cc33cf41244386dea2a4738fab0beb25a7b97b61529326f3dd7595a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/golang@sha256:c2fd3f640118634fdbcec80eba4e0b1648642daeec0903f729e30c6d16227a62
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/golang@sha256:7f2bd2ae212c9a9fd77714397a90eb7a4a1c6564a857089cd1453102896d0b70
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/golang@sha256:15f20041c972e4033082e13c3746be2726dfd353bd603098c2fc0f7b6b871f69
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/golang@sha256:0a6982ec8db8484c529dc34f2dea58c346c9c426650a85cba12a5d885abd564d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/golang@sha256:86853089dac30c987304d8a0af9d8b28799763bdf0b3a5e31ecf9eb29315f551