go
Entorno de ejecución · Language runtime · standard · v1.26.5
Conjunto de herramientas Go reforzado para compilar binarios en una etapa de compilación; combina la salida con la base static para el runtime. Últimas 3 líneas estables (1.24/1.25/1.26).
Informe de seguridad (Trivy)
Informe de seguridad (Trivy) · go 1.26.5
Versiones publicadas
1 etiquetaCada etiqueta es un índice multiarquitectura (amd64 + arm64) fijado por digest. Etiquetada por versión, nunca :latest.
| Versión | Tamaño | Publicada | Digest |
|---|---|---|---|
| 1.26.5última | 59.1 MB | 2026-07-08 | sha256:d79e890ef340… |
Úsala como imagen base
Refiérela en la línea FROM de tu Dockerfile. Sin root, sistema de archivos raíz de solo lectura, compilada para amd64 y arm64.
FROM ghcr.io/quenchworks/images/go:1.26.5O descárgala directamente
docker pull ghcr.io/quenchworks/images/go:1.26.5- Línea de versión
- 1.26.5
- Línea más reciente
- 1.26.5
- Arquitecturas
- amd64, arm64
- Se ejecuta como
- nonroot (uid 1001)
- Sistema de archivos raíz
- solo lectura
- Licencia
- BSD-3-Clause
Verifica la cadena de suministro
Esta imagen está firmada con cosign y lleva un SBOM SPDX y una atestación de procedencia de compilación SLSA en el mismo digest. Comprueba las tres antes de construir sobre ella:
# 1. signature — built and signed by QuenchWorks CI
cosign verify ghcr.io/quenchworks/images/go:1.26.5 \
--certificate-identity-regexp 'https://github.com/quenchworks/.+' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
# 2. SLSA build provenance — which workflow built it, from what
cosign verify-attestation --type https://slsa.dev/provenance/v1 ghcr.io/quenchworks/images/go:1.26.5 \
--certificate-identity-regexp 'https://github.com/quenchworks/.+' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
# 3. SPDX SBOM — the package inventory
cosign verify-attestation --type https://spdx.dev/Document/v2.3 ghcr.io/quenchworks/images/go:1.26.5 \
--certificate-identity-regexp 'https://github.com/quenchworks/.+' \
--certificate-oidc-issuer https://token.actions.githubusercontent.comConsulta la guía de SBOM y procedencia para leer el SBOM y usar estas comprobaciones en CI.
Dockerfile recomendado para 1.26.5
The classic two-stage Go build: compile a fully static binary with CGO disabled on the go image, then copy that one file onto the tiny static base. No toolchain, no shell, no package manager in the final image.
# Build stage: compile a fully static binary.FROM ghcr.io/quenchworks/images/go:1.26.5 AS buildUSER rootWORKDIR /src# CGO off makes the binary static; caches go to /tmp for the read-only rootfs.ENV CGO_ENABLED=0 \ GOOS=linux \ GOCACHE=/tmp/gocache \ GOMODCACHE=/tmp/gomodcache
COPY go.mod go.sum ./RUN ["go", "mod", "download"]COPY . .RUN ["go", "build", "-trimpath", "-ldflags=-s -w", "-o", "/out/app", "./cmd/app"]
# Runtime stage: just the binary on the tiny static base, nonroot.FROM ghcr.io/quenchworks/images/staticCOPY --from=build /out/app /appUSER 1001EXPOSE 8080ENTRYPOINT ["/app"]Este Dockerfile está fijado a la línea 1.26.5 . Para el recorrido línea por línea y las variantes de ecosistema (npm/Yarn, pip/uv/Poetry, Maven/Gradle), consulta la guía Crear un binario de Go o Rust.
Proyecto original: https://github.com/golang/go