Sign inSign up
Python

dhi.io/python

Python 3.14.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
alpine 3.23
Tags:

3-alpine3.23-sfw-dev, 3.14-alpine3.23-sfw-dev, 3.14.7-alpine3.23-sfw-dev

Index digest:

sha256:33a1c0b616f963259ee24fbac9e859221895b17b3f77fe516ebc5fe02c865216

Manifest digest:

sha256:12d215c1c64dba49386a6397b7a20721976ea4b56be2c3410ac67803c521b834

Size

118.27 MB

Last pushed

2 days ago

Vulnerabilities

0
0
4
1
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-alpine3.23-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-alpine3.23-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:d1c64e80e3b16b01a0965915db19062efa293bd64df2b95fd54ad7a01c3a0be6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:74bb04de91a73b2430e5f4b584732bf7715707988c45e5bf3208151eeb9eace2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:f4d7807a119b195191b6db90a37f9551eb608417b0e758608ce92d9211b39cf6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:2f51163e7496952ede9a722fa546e3579b72a4340be3c235187d118d565f630b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:2dc4fd7ee63ca12d8893765e8d51fbf136e12589bb56883f6bfc7aa92dd41839
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:6dfa407cd6c403db15d4a865484e6a56136a3834a604d44e0be25b98650a3070
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:dd0a92dc05b03d66db896ba39dfff8a469a20c4eb0523d99e50cae01c1ddedbe
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:87795b6d25270efbc4bb04675157756166904f72d8b882c50a384311e1a30ffe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:681ea45d331b64046b9b13ae00183f10bc5002edcfd4dbe23bb840df057c822e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:dc9733c25007f7e07317b548b10ecf478a76a8f37f2510a56c8bc8ea7c091915
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:c0b89d001e2f2fdfa2293a0d57129c8fd66a47a8fb0ba6437eff7afdc2c9a9d9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:df7b2f9fc81598ad984478ed35d281e768f29497568fd6e6f75ac7401317b833
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:e8e650856cdb65fd5abef9b772ae0550edeedc962fc31651398a07b659c0f108
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:fe991d9fdb297a1802009d483e1c5b5a61a6af468cc0a5f3145455afda69812c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:9cc1bdd4d4236dd7e6c2a65a2e448a42dec3b7eb49b9fc613d61a49686dbe468