Sign inSign up
Python

dhi.io/python

Python 3.10.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

3.10-alpine-dev, 3.10-alpine3.24-dev, 3.10.21-alpine-dev, 3.10.21-alpine3.24-dev

Index digest:

sha256:3e761fe1c69f6c3bb07525cdaacfa1a5f61994c4d9cac8ccf7db45d2b4840a9b

Manifest digest:

sha256:6c18f6d0036e13572d02d3a9c29f7789e0920468cfb9e577e072c799be34255a

Size

80.66 MB

Last pushed

5 days ago

Vulnerabilities

0
0
2
0
0

Support

Active until Oct 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.10-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.10-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:f32038f1efcfcd3da27180f998b9b1a2c402e30a971323417f8c4bab3704bb2a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:bcefe33f989c96f8a86328648cfbf1e9db280d91664e89afc9740225d005a38c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:d26c46021edcb47656f48b24dfc59f3eaf26c755c7dbed23c49ccaa193acecda
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:ad5787264103543ab0e0b689ab5d46183de55d439784164a5a2e68c674fee0d4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:adeeb644b3d2a5c568c5170dc6518ff1e1c195584be5da502ab2956aa0648e87
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:b141fffbd744678b3d19294d673a18e588198ca2764c45dc94fdef7a7e5471db
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:045d8414e552665f269fb059c727d1e0335fd489dfdc5343023aa981aeda9161
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:810f5eee9b89d9cccee1f2da7e2c415e95cd28f549b0831ee9e71e07d33d9c37
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:2e6cdc971906b0c249b3bc4509e4b75086c88c6d23b98dbb416d5a4ee7a47688
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:999f99596f136afd65a51b2ac728bce03a30aed14bbda275623df857e05c059b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:873ae9456a20114b0dbdc28f6cde36595e64a97ba0b8280d148c25ae6453f2bf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:2b168ca9a4c2ec4b73c32ef1e541e3e0a520b245c808152e46919e2df5933770
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:762c6fc07db74fb3b607a67eda2e06ef8c5e109a1ff087688c396c53315e95b7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:ff5f7c0e2325896d2d46f853ccfebed138d2d891946ba63dbb417047d7c6e7e6