Sign inSign up
Python

dhi.io/python

Python 3.14.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3.14-alpine3.23-fips, 3.14.7-alpine3.23-fips

Index digest:

sha256:61777985aeb5cf97048dab2ee073b29183e6e7c6704d49ba9d501fab4945a82e

Manifest digest:

sha256:b858a6cc293365772a5b651846b6c89c44720a96a36cdf2a82ba768ad09123f4

Size

18.74 MB

Last pushed

2 days ago

Vulnerabilities

0
0
3
1
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.14-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.14-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:ae98528b80daa325482426b6e2e58c5c30b1225d6dca76976559c4c215238332
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:39cb0b15b0f7987799f12fcabd564d3b55a0d2fb137c58b7d81ae6779ad8f766
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/python@sha256:8d9697c3a254d0190f98148ffd9abbc1e60478982e47aa2de78d4801a1ed515f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:df1a6189e01ffdc07846781aca82a061aa0765cd3066b1f9588f25581158d380
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/python@sha256:11ee745e0a411d066d911fb03b0824a8adac67921f1c2e91a785abf0bf4b5e4b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:ece950b6615ca3eb4545e849d74c3a66d9de9625c9684fa789622bd5987eea0f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:ac517463e0094fa48b6af4ac57beafaa1847ec732d6a93edd2e8e250b7e0ad6c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:64a59027370756a3f8e5bc5aec9f19617e05b1bd26d7f064b81408acea818604
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:3851e16442b9207b3969b484c8007b9b897e8031f4020d0da0c7d5f8aa71792a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:d9b4881504c5c61efb6d896ed036823779ced9d5da1b2420145b5fa02d073f47
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:109c3fc5ac600a158a4b4b173717e351c2927c75844d67343d039c61457c5500
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:01bb07ca889d98e52ad3d68da8ef985ff8bfc38544ec4f5233a154f68d53707e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:4b428495d140f14af96ec434fa60bd51715185abce59cb5a02a5dccf94642c3c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:11afe0a47209c3d5435b8b68118bb270fc3308de56ff8cc00458cf7556763329
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:b6ffea77859481d2b123649a63614f51b2a0548da08ba45f1fabdd9047aabef5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:cceaad08b7567281b0c9b66f9bc351857a9f61f0a573ed5ae8c24aacf853cb92
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:17350b7fe3f4d489e8b4e33d15d2b4c04a11cb4f25efee9eb5dc55a5c2c72a63