Sign inSign up
Python

dhi.io/python

Python 3.10.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
alpine 3.23
Tags:

3.10-alpine3.23-sfw-ent-dev, 3.10.21-alpine3.23-sfw-ent-dev

Index digest:

sha256:e2c71b0e21d573c1bd599316da09184a03ccd0f79afd9c3ea3bc116c58b13856

Manifest digest:

sha256:6a3e53e85cf4773e55e6fc657fe205b737ddc80ecae16b9098beacacdf083580

Size

118.23 MB

Last pushed

3 days ago

Vulnerabilities

0
0
6
2
0

Support

Active until Oct 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.10-alpine3.23-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.10-alpine3.23-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:1f53283b66613bde25fd9144699096da8dcf38aeee50d6932d314f39ab466eb3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:28e82846175b908ecb851d9e23733bcdbc1da69ec9088146727d4e5a325612f6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:39bad03ac210b18e3cf3b7bec929e9624662aaeed3e1c72d74a3f8325b2f675d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:785fae7d669ada514b2abdc1373da46e5687b8c3fe06dfb7cecc1c37f68bb6c1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:6ae7043c5e299c6054c0ef92299c324e4d3575d4c6b505cc59dab4caeef8d2e4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:8a8eceb87441c93a491aa62cf62a3d0656eece786ed677c74d85632923493cd1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:de18be07240e60bd95b19e3975747d010eeed6af8c97659b5b14c0330423bc43
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:a393ea36623f1a5790b84f9bbe6afb5b073c79fbaa7d018c2127591c42aaf044
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:24bf35a572d7cc123260d2175cf23fca52840f6440552d3f14f41e26fb005806
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:238900dcc6ab4c8d6af8985bbea3c80728585685b5ac5edbbdac0f7ed4bec161
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:c6b8c0b67fe2b6abe808770b9df062c62da73b060e826662b0a2f83f10956f72
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:04e3c393d0da66955c127d02b88bee0b3a1cfec49cbb0ee17977ea5b878489b7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:5f1f051f0e86d1eb8fb7118cca30851b15e05b125ba08046597f249ba445ae3b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:0c204b16aa1872be54b22112a4ad73fa199bfea139fc35f402f5cf106e011ff6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:a2587bfeeae0e65f4cbe2a04a48156ed718aa3ad3dc1222251de40b81ea9ea03