Sign inSign up
Go (golang)

dhi.io/golang

Go 1.26.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
debian 13
Tags:

1.26-debian-sfw-ent-dev, 1.26-debian13-sfw-ent-dev, 1.26-sfw-ent-dev, 1.26.9-debian-sfw-ent-dev, 1.26.9-debian13-sfw-ent-dev, 1.26.9-sfw-ent-dev

Index digest:

sha256:6cfd190620d0cde4b0ef73101404c2697b4164b5c9b2544d6756e89b4ee8877b

Manifest digest:

sha256:86b1f37c6e0424ceecff416335592f4565c8d8532635e22fffc80c23b5a2ec9e

Size

194.94 MB

Last pushed

17 hours ago

Vulnerabilities

2
4
0
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/golang:1.26-debian-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/golang:1.26-debian-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/golang@sha256:8441c05f68d5b5218cf9296c13ef2ec66e81242c75fcccc4aad9c47022eaedbf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/golang@sha256:e6387bb552e13786c4db7f197eed6c0667d91442ede404afabc272999eda24e8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/golang@sha256:c66c0f4c1f884fd48b34c6f7bd22e82106b61f599bae3e18d2d914233b2edb88
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/golang@sha256:c00008971646ff08d1b2a12b7d8bc3c0213d71b98ea48c5660fbbae1f4aa877b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/golang@sha256:4431ecf8dd6797fa0ad42f898342c14292f2c3f6aafd1e8ae5921f619142c690
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/golang@sha256:fb4a48b7c122bd7471f3376fa3b5899af81e4fcef3df4b5850de7509858f524c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/golang@sha256:0531112a64a10b443b1dd42c1332d2fce0d0603f61b59f8667e7aa76b312f840
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/golang@sha256:95c7b7698f91ef69a0b449f98535abcf92fe0fcc57714f917e4b0bfaedabb6b9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/golang@sha256:0986e706abd3f46ecb58d95d4878560314da072ed8f66b84701a32909bb7e026
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/golang@sha256:d40ddfdc681a35b845dc36f2045566371ec11b75421ebe34905cad24da57a9b5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/golang@sha256:38cd977626548798058a56ce2ead064b5389793a5c6220cd0efc8e92a40a7018
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/golang@sha256:b844cf3e5e287793a78a7c6cb84afa6a6053386a4db0aa41b45e1976b58eac2a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/golang@sha256:966f78f435a7807049ddee7292c87dd80ad25e6ae887ae73b348e8100dc5cbd6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/golang@sha256:1ff0f030f3e36eadf53a4c19f436fb7d0732e173d9e18aa0949c0f5841e60e7e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/golang@sha256:15809df50d465d7d5377c180a57839e94046fc82685ca635599b64e366166663