Sign inSign up
Python

dhi.io/python

Python 3.14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3-alpine3.23-fips-dev, 3.14-alpine3.23-fips-dev, 3.14.7-alpine3.23-fips-dev

Index digest:

sha256:a4d939de9be1ccd61eeb04a9c02ab6843fced17ad5cdaf3ec8aad97d978c21a6

Manifest digest:

sha256:d9506b075335403050709be933222faa7b5867016b150a43ff618918dbb58f9c

Size

134.48 MB

Last pushed

2 days ago

Vulnerabilities

0
0
4
1
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:ce16b9d62eae37fe900ac8eb0aa4a7f615ffafc2c5bba6fde57669e2104af99b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:3d84bd7df3c717b76541cef8b4f45d87121b4823677450482ca065c4ca06b017
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/python@sha256:cdb9f320d11ac66a274c486dc3e885b1386d10bbe24697450344db8f6a54cceb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:ec4016fd2cfd98ee61ae8e502a7bad3a74d7390bb80a056c6c3d0929bfb1fbf2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/python@sha256:1a4e049de221f3a9787103643697f1a782e61e7b54a04a6fbf03a549289cd341
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:ab6c2bab2235b9ff65fd4813613514a9e5f585d22811ab41e2dbbb8512f67ffb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:bd468efc6a5a4288fbcd4fcf9aa78d49672a976ef18d7c6810946fbb454613d8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:0f2302f11a384d98c9d3df25702ea87e1d30538d73c058e386d70e1601d6f739
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:df115ac12fa9fc37445bc4c09d663d98e239561a7db842ff73a59e01cf35d786
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:3b38dc929ec1176c238f4c8a9939b9046e9fcd18cca43019f2934e18fac92b4f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:f28a8548b995c92bae4f62504de80132a0b9482a4a4357a4d72933b4fbd80fbb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:5febd3e4c5bfa307275f483d726699e00dab74dd45b0ce317cbf710cf51ba5c0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:61fc81a4e26f4695558a0ef283eb77f14d866e561baecefdc2f2cddacd650380
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:a8719c4c714299c92e913a531746a3f4636d17b6c8dda1ec7634852c31ea16cb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:42a33ba9ce50bba76506c8ee73abba8033b47322d4ae7969f379cd9921a63ded
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:28dcf435b9d01ff3a183227d7595ba14b558b3d9ad6d058322475ff65a00035b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:dc230f0f2d54eaad4869ff05ffe07a2bc9ac5c3693f54ee20c5d3eae5bdfb46d