Sign inSign up
Python

dhi.io/python

Python 3.14.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
alpine 3.23
Tags:

3-alpine3.23-sfw-dev, 3.14-alpine3.23-sfw-dev, 3.14.7-alpine3.23-sfw-dev

Index digest:

sha256:0e5978defa5f4f7ff97d505552be4587df9354ada9edc513bad9f882a4b5f964

Manifest digest:

sha256:ce0342ebc2db01a25510e256b3a272fd156087a90957a65afef359e1e9a4fd02

Size

118.30 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-alpine3.23-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-alpine3.23-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:8081dbc33d8e9542cf285063156dab49ab38a129eb2bac910c0d80cc437b811b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:15a935c964cf0c80048bf3dc9a348251b32a62c65b5e8b14cde2d692a5d10e38
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:217cdff640c90925fe7860d0bfcd7cf9bfe7c7d5a3b2639f5e737da06d9fd2bc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:7f081df98953bcb2f17e198d49ef797a981de1d6366407293c763e086f393f3c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:e71f33ee0d6d37d998d939ae764741b3c2e507031e703d0fc5314b1c9f727bf8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:97640e699d224e57fc314de8d6926d8e121eaab6f2f4cad8a625edc07c6e2ebc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:d81e4c9da24e31443350df9ca3b21c69a87d92600eaae29785680fd544279923
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:ef6b48cac1c96c807128e5ca04772519dc76a716e97409b311ca3f4d80d3c4ab
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:4886fdb22eeab4cf05e2cd40c583d11237c2f4df3e5ca9c20260a27b39853017
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:ba296c601bd734b087346b0e0db584faf20ce48d381ea183e0c04834a34d336a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:38f828e79cafe7f1ecaa8e7f327c256b38686395a958797543baf9b1a95c7ab9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:4eb26c56e7c3784b9277d9478597f1cf9e1818008c06139dc8917e81809653f8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:992c124ecccd64cd822cf4e7d51c3c2b4c41b0f9857981cffa21ff01721f6e4a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:37371b24ec034a96de437e9d77eef114f3ab405e9573835a74548e69716a470b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:bbc15f759fb9221dce29431e05ef42fd08d5d21dc387c9f4e8a2f43821bdca86