Sign inSign up
Python

dhi.io/python

Python 3.14.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3.14-alpine3.23-fips, 3.14.7-alpine3.23-fips

Index digest:

sha256:70ed263e300cce32da8a2dfd940c27ca44d454d4db8d56dfa9d9be3717f94e11

Manifest digest:

sha256:e3d6232ace26c910334022325f4fc66fa63b02ef82d9df62f74daca334edabb8

Size

18.75 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.14-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.14-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:f215736666acc5f39e61232d7a0bfc5f5aea9ba7c989d130246a5a70367dbccc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:6ddc82355ea411badb9f30bb53774c3fba0347983b7844dc9dd1e90b5f7eb811
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/python@sha256:22f51b0eceb177c6dd235cd6d3fab6ef541124273681f19901a16e9543295ec1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:664b920aa67a748e5b75b12009cd47c71db77b9905748aab9080037fa5242422
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/python@sha256:f5a1c437c399e638362996fbada2fb92f876cbb1460866d4de360d3dbfce5958
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:a18c20e2774894a72ba3f1e8c327fe5c5d7116e2f7925dcc34e5ea4ca445d6b4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:638eb6bf893526505af5b885be6381e831a43d5816c9203a8a01bdeb16c434b7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:ae81cbdd5b85e735009bbe1b4c1fbc2f6fb8fa87f97fc0d4f72b6081935ac849
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:3ce96daf9a2a52abd9672261c361fd8f06db11f535229b5eaaa00f2d40cb96e0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:03066dc7feb1ab4eade5e086e83109c46aa3d03f3a98b26dbb5df8ba22fa4637
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:9e53c6f041188f7c51cde5f1ffbc431fabeffbe5ea9fa21fe88e1aa79045aa9f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:0af1b005cf00ed38269574c3a833dda4dd2cf3ada56f9287adc4d27dadf65d75
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:5197287ed555475989a295edf592baacf2facaa689a7b0c353f64f10c1efe4d5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:68aab2629c063be4dacb74b1452d04e71ace059b047d197491ca5cf15edc24cd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:19f8befde9f4dfa256045ee585e5c2c365a8212f72ad5ffeabff148e79ab0640
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:43feb3fcf74b393b32a638b24b9517feac6b4d8c1f4356680f056210481456ff
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:b51404aa516b3a1c16a4237b8ce2d91ad6acafe4dfc825376b2c4e26f25874d3