Sign inSign up
Python

dhi.io/python

Python 3.10.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

3.10-alpine3.23-dev, 3.10.21-alpine3.23-dev

Index digest:

sha256:21d4e05b7a38aa3f54a7c78ba420dbc1d04faa0d91fc9e9f89b850452b886bdc

Manifest digest:

sha256:d04a5db0fe056eead6247c4eeb3b0d3995ed613532fe9aaf2d442aa22baa4e4f

Size

79.84 MB

Last pushed

1 day ago

Vulnerabilities

0
0
6
2
0

Support

Active until Oct 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.10-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.10-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:814d3580a7a86ff8d43b5deee9f0e89afc03e61db16749c2b3769c7608f338e1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:e8fa281c10a58aadf8f46ac32dd7b22f433707b528de420922a04e33a8360db7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:feea58bcc2c7eb3fd2b0d2fbe4cf2730d96583c6272638c3cb6d6b05a0cd58ff
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:ceae499bfd7171b5986c26ea1bdfcc9583c6418f35d200b0e370a416c458c461
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:52d58c69e6841d36a8edc7ff112b353eb31e476265ad270cfea23424e3125375
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:650c9ba771e7c0adaf99a9214e7bd48eea5d741cba795d1d9d1370c256e220da
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:a70b30d727627c2c28cfb39128cab9e47ad3b04e2f0d4c7c1320015736bd0d95
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:21aa5a5ae19c73d0fd46450ddbe8de63fdf03124ed5ef2dc4b955101152450ca
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:d0e8e763c08a0c2a827b46e0999f33098abacc5a78a5b05f37b81af0af426afa
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:a84ca7398a63b3dc23297a4b39e40161d89f2b76d9faed39409d8e0dc24f62c3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:c1e2389b9faaa85c7ec1a001862fa547a2644ef9d4b65e9f62ffa415dea1422e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:d8671a14fca9416db5406dd67c5a0b8b8a753796ee8f8470992d57c67be480ea
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:05ec779bd3e3d867a398cf72c0853b112f0492357ac6f222dccf008f3ddbfeb1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:52c53af9d519ddf7651b367f54dfc7e59bdec1e8ee05dc67219ab75256e13942
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:b1c014c0102ad476fd6ae57f603ac3dcba03f3b85b0d8b812ee970eb2dd663b1