Sign inSign up
Python

dhi.io/python

Python 3.10.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3.10-alpine3.23-fips-dev, 3.10.21-alpine3.23-fips-dev

Index digest:

sha256:97d3cd9aad961ab6f14ee196ff25e5a40e7ab0d7d3d6623a7ca844790d3f9b3d

Manifest digest:

sha256:0edcfcd5fbd7a2b4d20866acf8d99f4242afb40b1b4c4d6f5202b846d7f5320e

Size

106.91 MB

Last pushed

2 days ago

Vulnerabilities

0
0
6
2
0

Support

Active until Oct 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.10-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.10-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:49d8785dd6086643afa0a4a24940004df923cc5670aea228139859af3af76943
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:6715b976961bd43ad4e43b9cd10bff0e2625f00baf691982dea9707308afb257
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/python@sha256:aa4c2914cc6912601076d33fa36ef6b8a1e9864084e5a1ce2559e2f6db8acd91
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:ed9b3e2c531422179d7db32f96dcced7a7758affde001af4f4de21931e52f83f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/python@sha256:8aaad29e511215c4fb1592a28c0fcef486c6ace3c6a7009e2b38b5d9b519eafd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:247f328cde06913becb3a18aa61e1ed199aa3c4fa29b6ace803909ae5b5dce58
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:21ebd15b334ce5b110c091e7c0ba071422a43e2e69b7a9c1133fbcbe58e2c2ef
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:6751cf50ae11de28f50f9734395baada0f17bb0162a16c58bc49ed588a4cd8cf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:fb24b692618d1f57de9e29797a5f001ced71445b0b4e5f5c44ec54f9c0f50298
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:55b8c38e92de5283c65ee259fe0cd082c04d174a02c2c4c87636ee0b2cfeeaa0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:ead3426cd6693e48729243711a5bb7dbf687ecd6c56fb1b519e383ac25844384
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:90113fe0a67f88d120a134c0056efec0b7eb7fb5ce8456255cf2ebf57691cc9c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:2bc76290cccff9f8329ec991d199af5b560e2f49b8fb962f908a1ec98452cd8a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:08cedf0c4bc0030cab01d60cc6822cd7a171a3aaf4af7177d25856f86694d21b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:6bf5f4371577aeb0d88c8403d278f0e2d6ecb90c47b6220661564325affebc87
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:aea5e37f9bf9f65f439a80a6eb50e6eeab8d8b354df641956d85bb1c50ddeaed
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:11904222e0960e8d5695346315f2341f61cbe93f6d71a70a429d35989e1ca07d