Sign inSign up
Python

dhi.io/python

Python 3.10.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

3.10-alpine-fips-dev, 3.10-alpine3.24-fips-dev, 3.10.21-alpine-fips-dev, 3.10.21-alpine3.24-fips-dev

Index digest:

sha256:b9f41370de09ee4ad1cb33b7316e6b83354fbddc6aa945bb81221fe42209b9f5

Manifest digest:

sha256:24dd2ad9fc6219094ccf18beddc7854dac8eead6feb6621f9d1f1783c69ec0ac

Size

107.71 MB

Last pushed

4 days ago

Vulnerabilities

0
0
2
0
0

Support

Active until Oct 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.10-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.10-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:cbdb7c4281162c5a6ecd5154ae6821904501a78c41a12cde0184962c9ffee219
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:c47cdba9ac8dce37209d43dfd6033e4e307acd58e08e62c2ca473ae5cfb76f94
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/python@sha256:131a741b742d6900f954e4858a793e92788b0cfaaf46ff47486ef1e735f40edc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:da108b4f349d76cb0f089a3f600947a275f9277cac34ba7a323d8a1256bc6626
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/python@sha256:28da2277875e876784bdab356ecb371058ed5a3fa6de21ba0d123984a30fac75
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:f1c29395d7b0d4251861b51232786347abbc0c9ac631e103c6c595a4dc3e03b3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:60ac64d26eb8acf28067e0542c47354a775bdb242b19cb3590948ce7138a31a8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:6dda74ca4244efbd05acf9114cef0536be6ad693dc1253a2cdd2ff9f226350f9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:ee8748ba8d46606eab64e4e2e16ea3f6099667179e3967b87cd983f97dfa7d9a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:7a774904e17fe2d2f1ba1f4300901ced27cb8b6d2ecf72e44f46ee8a9d1a04ba
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:b384418f0ea2a57c140c3c3433ef876efada87585a2a77a4eaca3110566766aa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:b1ec8f0c336d164f91284940bf0af8221a82b6e5faae25013823a46b70435dfe
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:27d66323505b292823c73c4f993f1e0b48c31893865aaa23755cd24f2aa1d905
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:5aa209a0ef5e425f4de4d8106f5f65315984250cc1b9f01ca1c369d60a7bfe51
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:bc039e6c009ff5f607bffb939ed93bf6813197df8f4ccde80e3d9473eb731534
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:03592694ca8a02405774e860f3e2f5d51e93cf5b5766194168c489ac77a1136a