Sign inSign up
Python

dhi.io/python

Python 3.10.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
alpine 3.23
Tags:

3.10-alpine3.23-sfw-dev, 3.10.21-alpine3.23-sfw-dev

Index digest:

sha256:489e1bee34848372fc5bea69445e8884e8853a01fc71ce454f1c83289569a029

Manifest digest:

sha256:a47fe4636e54c362ed5f943ea1886d6953de34d3e88818ee4d1bfe1d3d8e8a36

Size

117.50 MB

Last pushed

1 day ago

Vulnerabilities

0
0
6
2
0

Support

Active until Oct 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.10-alpine3.23-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.10-alpine3.23-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:97f44137452e94871f7b981ad8824a35e03b860a07b1b28e5c326b7f9bc85547
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:8b8a01797066347911a4d9e43475a2e64c8c5ac79083a75ffc4241a84741f39f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:458ad0745ae9e7a74cc39ae3b100e231f03bc9c06c72b69ce3a14079bce9e796
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:ef745680fd98dec770628fabffcf7ccc34e4b61e7408f63b171dea757970511f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:d834ae6e2daeaab16b3adcc35798b36b95c55f4254ec0dcdc5f12cfe9cc06e57
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:621b52bebbb2ca892ae9c23bc8c40f28dca3734611d0035cedca511907c9d357
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:0793af746f079651af2c689babbf5c970d6f79b350d2c54b013c3dbf8552d210
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:579a6de22e25dcc53f79245b541d4fff0edbb60cbdb6cf10b078f324951742cf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:d579fc871d83a17f4f2e80ec962cdbc2a7d944197be79f56e4e45366d100612b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:d6e0f03b90a23a2217ed3a5157d6a3b648c8698cb2d0ac4566b51d0160654ebb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:b9c4448604877e2b8e96c83d8e10411faf68f16aca1ea14a340045c03c98ce3d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:788ca6b677715349228637283b6fec5ebb1c6de864df5253157319ef2abf9e69
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:33f083008290589da9f618d50ca97d49e12b536c93cdbc7ee9f9d44b950cbf3e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:a7213ede61817bff9d3837f600022ea9aeabd5cbc9c0c71300073e1a13141523
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:aca3d1ce5d0f843cd7fa9313058c2b5d565fab72f54b1604e909488b57673ae3