Sign inSign up
Go (golang)

dhi.io/golang

Go 1.27.x (msft, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.27-debian-msft-fips-dev, 1.27-debian13-msft-fips-dev, 1.27-msft-fips-dev, 1.27.1-debian-msft-fips-dev, 1.27.1-debian13-msft-fips-dev, 1.27.1-msft-fips-dev

Index digest:

sha256:c9a2466ccce53e1f6f4b82343deed0d701af384846a4419612ca37c2ad885603

Manifest digest:

sha256:e639bc9024b97309726b2fa977dbd38a1a0f51c80a04f644c371d3ed983bd818

Size

179.51 MB

Last pushed

12 hours ago

Vulnerabilities

4
12
0
2
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/golang:1.27-debian-msft-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/golang:1.27-debian-msft-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/golang@sha256:146747a6098edb1d77043d3a4406c521afe4b5676a98a5235ed92dec6ee81787
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/golang@sha256:46ffccd3b6bad2c738e4854235316d636efaa529679b1cb61bc0a0190d8b921c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/golang@sha256:dbee29320038cbfa9c60a86890bd93d53fb04d23ee25b9422c51d4fd2816b592
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/golang@sha256:f056742ade82e12d52874294505b19f2c4fb7125d13a94e747fc62e7ce845b31
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/golang@sha256:cb224fda7957583a51ae12f3b264b4b4361272208c9706072928d2f0a18d06f9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/golang@sha256:f860efe8c0736b674d143c04ecdd5e4510f49d9f32b581df4051b1414edcfe69
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/golang@sha256:2076cf8217e58b56e7c82d01108522e93e8d3194d8f355d3f0aa3d85489a1a23
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/golang@sha256:bab28a518b07412ae0313452c444972de0dc28aa1bfdb64c8d0cf73d0cb2042b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/golang@sha256:df4869c3bcda740925f1108f76a1ae270998ac5da1fa09bbb8d3f87d56f194d8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/golang@sha256:2af8f43859d9a0ec4e75a1c620e17da3fa0158d53ccea866b5ff54ad83569854
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/golang@sha256:6d6fe57b6aaa0926826e0a2650997e77ccbea68e1120d551d5315182d741066d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/golang@sha256:f7602a9fd694b8918a68fa12c591342de4004ff808fe1db37431b88c0c4f4d87
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/golang@sha256:b8fb3f900fe8657721ad2f514abcaadf31620f0372b9bfe0a448ed91fa1d1d15
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/golang@sha256:37122f1e85504377f0ece965476bfe34dad929d72dcc1f6c2e7c6028fb5d3809
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/golang@sha256:109354cfdcf9e8677846f3824a6f9202b64433844b4cdb88b3cc8a39f700fae2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/golang@sha256:fad692119f2477aa21afff0212ac305f809ca9b8047b7af5dfe93d5a839adba0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/golang@sha256:0033c2d65489a08b896e9756c5f9e8bdacf3f0586285914700fecc9de327ca87