Sign inSign up
Go (golang)

dhi.io/golang

Go 1.27.x (msft, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.27-debian-msft-fips-dev, 1.27-debian13-msft-fips-dev, 1.27-msft-fips-dev, 1.27.1-debian-msft-fips-dev, 1.27.1-debian13-msft-fips-dev, 1.27.1-msft-fips-dev

Index digest:

sha256:40536ed02894823b2ae0697b6dbe0f711a77b05cd4078cb482d91a4bb8591c44

Manifest digest:

sha256:b06dde29d72a6b15a6dac27b1d711695ba8dee8933f9316745405d5fe39b29f9

Size

179.49 MB

Last pushed

3 days ago

Vulnerabilities

0
1
0
2
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/golang:1.27-debian-msft-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/golang:1.27-debian-msft-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/golang@sha256:17e53cc70113dcc9fed70a0ab9b89776604e454ee1bff29c050e91017ca8dbdf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/golang@sha256:464d9cd2ba5410fed484fc503abd60f9be8cfb850242273be6454e041f2c8d40
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/golang@sha256:0f42750d2b099babe1b5b341f0bb8da8325cefbe08739031dbf5774c3315ca98
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/golang@sha256:e29cbb02e55352facf75db1026153e08d86bc6d197c9cb74b59a1173f91ee2d6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/golang@sha256:b6a49a92dd3b6734ba6492b636bfe70d80bc2be1a65f9bf98e23b6eef5fae13c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/golang@sha256:381b52c72b9552cd49d7558e721bd8be07f8031f45297bea388225f0dd05c6cd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/golang@sha256:b4af47cbca1ce6a7e966123e1f502850b9dac74ebc84fd5565e2631b176653f2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/golang@sha256:17cbc823a42dffdb9222dffbde418a47f5600b94191d6afebd32fd8cd7b8f267
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/golang@sha256:d24a18d8f0b2fca490cb5354a2f40c428c9b28aa2e9cf2e023803080a61fcb72
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/golang@sha256:dac87bb4618f6176e07d02aadd5f65a143553a6d0dc9ab1da6c90e4249e8e984
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/golang@sha256:5bd74cf63052cde638d2a6d8f008676592a0883e278b65540b29be49e5280324
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/golang@sha256:7f4c8dffdda6750967db57c21794073c4924e08064773022410c49ad1fc8db96
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/golang@sha256:12dac02f59cad3d821397b958a195be702f672ef9446e3babf2058c190e1413a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/golang@sha256:073d1d75e5ac9261b55934ab8d1dcfd71b4ddb270d3ee6b5dcc693aa39803300
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/golang@sha256:0254bdc85cded26d5e28febb018a697829165d7238925802443be904b539a42b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/golang@sha256:d16b9dfb8fa32ac79431dc829ac5ecf35b6aee1ed0a66564889db24ec099eec8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/golang@sha256:97ff72974041955944b9c5fb4d47897790202032204320ed1451669ec338cd5e