Sign inSign up
Go (golang)

dhi.io/golang

Go 1.27.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.27-debian-fips-dev, 1.27-debian13-fips-dev, 1.27-fips-dev, 1.27.1-debian-fips-dev, 1.27.1-debian13-fips-dev, 1.27.1-fips-dev

Index digest:

sha256:671b37632c40bd7611df64e68372a028199a9931cca800d4f2732906b3f2c9bb

Manifest digest:

sha256:f2c737cf582ec390a532edad4762988095f1725bc4000128cab1c3f9484bd7a6

Size

161.51 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/golang:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/golang:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/golang@sha256:c4535371c24b35ba98ba8848350e3902ed271f9c2b056b65d49727e10ee5f15b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/golang@sha256:6cde6ff0533afdc8c7bdba8655b58946676b6ee65466575bd7e36299c276412d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/golang@sha256:6aa8308ffbee4bd7a447b1812159e83643d3ec35cf1c7970ecb45d0e2b0122b1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/golang@sha256:8ec0200b3aa899f6b77f40c87a1ba671bfd54b42d475f2b1a2297b90df3ef3a5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/golang@sha256:f1396db913539796a7a1a054388b33de35d0beb90ab6eb380bbe1984df6636e4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/golang@sha256:80df9acf1e363981b5f7d7e67fc6b22a1319fa647cd1f33eae04e1e789bcf8c4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/golang@sha256:9efb772d5150e8d7562235bdbd17231f507688a70c7a2f3f7fe69e874b7b82d3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/golang@sha256:861db71d5c1c741211da608fa473527a61359c8c0dfa3c1dec255345d9a29cc2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/golang@sha256:4b2d224f896ac8fe089ca249272440f5bd67dcb02038c58869533808bd49f7a4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/golang@sha256:cc8a09c3636b447da582113164dd704f12ec23dbab5c4a65fe23afaa83e87ef8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/golang@sha256:b80bf8740601f788dc57bbbe773c0a33705308f19775218248bdec28e08a8b22
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/golang@sha256:b6ad8f72d34d1816243ee31555fd9beebce7532f2c0dc377d706e3c767cccc88
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/golang@sha256:ecf58b9a0cdff740554e4e298a4cc6fdfc4fa5afe5760a3978bbd8d42c364414
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/golang@sha256:b5bc77ed0cc2d0a9204481846555782825dc866e0513cff825e63cfc39733f46
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/golang@sha256:ff05754973769b62ae72f4715276a604274e1c1efc47df9a9af579c5d1c79cd6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/golang@sha256:693e3b520677676c3b1fac4513298cb1b769569b39383504847801d3ae82c885
SPDX SBOMhttps://spdx.dev/Documentdhi.io/golang@sha256:2be6ccf400b46342bb91439481a9f97f268b1a6a91c9fbe6f35d639097dce9a5