Sign inSign up
Python

dhi.io/python

Python 3.14.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
alpine 3.23
Tags:

3-alpine3.23-sfw-ent-dev, 3.14-alpine3.23-sfw-ent-dev, 3.14.7-alpine3.23-sfw-ent-dev

Index digest:

sha256:e57d36d22f5e0b2d772c7ceb99ca7d6c5964bb7c21a5e0f4521aeb73d65ebfc3

Manifest digest:

sha256:d33e61b4bd7ca131688a69aec13eb92358167baf6d11821cc7bc9a4f237e6f8b

Size

119.04 MB

Last pushed

2 days ago

Vulnerabilities

0
0
4
1
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-alpine3.23-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-alpine3.23-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:0163f1bc90c5c1bd72bbd02c37b570cf682399c4c549fb2888d952e87ee3e1e4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:83875397c8d59519f0adc69c593770d650b154bd2f78c942671c98ed975bfbb2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:20784250aaae1031ff59968f6f3991b6db21127532df95133626a2902216853c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:6b2e76345e1e118fc877d5ad59fdd89ce271ce4cdabef128715e5339e6dd8ac5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:020197cf5b690d4d602245ecae06a42bfc911d162f6986922aab018db85b98b3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:5d2b2d09a8aeb63ce6ea85b4424b7b19dbeb86e1e540bafa17ca56bb672e4f85
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:bacf9c507643e5ad2954179feb08f60e9fd06f121682a9d55d13449aa5da1bad
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:2be4dd3089c89fc72cb4ed60ab5d682c026b3e4d5d77993af6e11787821970e2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:f55483fcc8bd74d2d4ea57b4ed92e280b508fed001a2ecd982e102dca9052222
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:a5084d9c76de0acf15fcbe4a056c13d9323b1284063018a3bbf314f70085300f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:6b0d4efd82ae5d6f0096ddf75414b21f1187c2a0f992055f432720d7f830b5bb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:563e072ac0fda986709353edecae16b873234ce06d8e767d949b6ccfefe5767d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:3736a02013070081cd50dfe37573c465add2021cb3421b942caa17202c672b9a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:0edd439998b458efc9ad7f944551e8a9aa2e8633263bee9e88b06ea591dfda95
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:1815be213dd5f09c998060dbdcc3ba734e896abc8efd6272bd349d7a757a4912