Sign inSign up
Go (golang)

dhi.io/golang

Go 1.26.x (msft, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.26-debian-msft-fips-dev, 1.26-debian13-msft-fips-dev, 1.26-msft-fips-dev, 1.26.8-debian-msft-fips-dev, 1.26.8-debian13-msft-fips-dev, 1.26.8-msft-fips-dev

Index digest:

sha256:fb2f38eb178996cc7839cfb4ce954db7b1866f1439580c0bcd40782f372d12bd

Manifest digest:

sha256:a89296659e178d261462beea5a633e74415151d9e3ce9fbd25b4dafa7171bc90

Size

174.22 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/golang:1.26-debian-msft-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/golang:1.26-debian-msft-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/golang@sha256:719d6964dfa8ab8bc4380d325f1d7a7be8e178e2a7a0444fc6c4d328e88dd462
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/golang@sha256:26dccbc944b5899f8c1e607f1ea935cebfd767d17dc3ba5c5e99834a118e87d9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/golang@sha256:0ddb15f1ae491a5af728b42b460e3a15aee52b9d403cee27e298990a7806a8e5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/golang@sha256:27ecdc0ef5723f37f52681f6bf18feef539249dbf4d47d48ff55ee1434dac739
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/golang@sha256:47e75b25885aeffa885a07dde555d0f4a5b0dc25343df563ed16cc8b99ba0a61
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/golang@sha256:ef7e8f8fe0e1bd649c0c8e8f426c0c2d6a772f0d54f5152ace3f167dbf94dd37
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/golang@sha256:74a0b342bf4a47ed3b7b7650f89d277dad8f0ab28884dd1e91afbc77529e2a8d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/golang@sha256:47bbb6122479a65616005e1f1701682bd43cac04449c711cc817110d4f6b9526
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/golang@sha256:72c7d2c286b69f00ae7fd33bc62f0f1662e22c6fea73790c4d707500cb8712c3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/golang@sha256:688db5727ae342584ef5d35724c4829bcad0508465b0250b45e2142ee6a54cbe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/golang@sha256:014f71e1042d45d7a7ef130662319ceb2175fd8a8c89389aa94936dda1ba6986
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/golang@sha256:203ce4736903dde0833469b6efb8c60a48b268cfc84d89f5b86d9e81da7182f6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/golang@sha256:eb7c8cdcd8ee6f43c29fc5a493dce637ae55f630b0c7538e7eab6f45180dfdba
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/golang@sha256:f99912ee03637c4228411a760c358089a611871fcd23310ae82a5edf6a10ee50
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/golang@sha256:dbe33fa28b6e7dc35b469a9e8d2794bfac66df84366f27839b0126c0ef04057b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/golang@sha256:f6be5f7e9a569c83d968fde7a96d6323848ac653a5e2bd4ef916f7ae9ae2147c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/golang@sha256:01a4dd5e4861237e3df4ac35502c318cb2a5868562a3ce20a587047dd80a4e9e