Sign inSign up
Python

dhi.io/python

Python 3.10.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
alpine 3.24
Tags:

3.10-alpine-sfw-dev, 3.10-alpine3.24-sfw-dev, 3.10.21-alpine-sfw-dev, 3.10.21-alpine3.24-sfw-dev

Index digest:

sha256:e6590e93a4782e432f586356063443bdd109bc54a131be0d2a9aef0e3a2dbb72

Manifest digest:

sha256:06dadfa66d98f8fd936d4be9676fcc0e677a0355fa6bb9d25d35b328cd4c6243

Size

118.32 MB

Last pushed

2 days ago

Vulnerabilities

0
0
2
0
0

Support

Active until Oct 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.10-alpine-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.10-alpine-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:6a34c792a21b83ff2855c6fd9905d3830fc06a07b92ca1b0efb074e01007a3ae
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:867e36413f516996e9ae1e64fa4db6c59b30e9ae46237a80e166e3bba76c107e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:d55fc39f393312db588cb0c15f7246605ce019e0170d856cc67b6fdf7db9d1a4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:e550b1cf2f49baf83a1e61a23d1020a59826b3d438ce8e1092f45221fa0feee5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:ff3ce854cb43c7840398d54ae1e75dcb83d52fad7e30f015e620786a75494b12
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:ed48d11281103d21a6427b5f703744e3f1f843b0321f2ea0c386865ab8791bdc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:ab09fe9d118090212fb34eb893f768e2067bc6062056a924f9b458d3347f925a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:d9c24a299d235d2d05f9616c14bf92e6736fc7b7c1957358b62b7698ae7d0c0d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:efd7b9cf086be67f01e47929f774f670466a7ac398c93a74f549a9f918cc01f5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:f52118c0142ef6f19a4bb03014fb149956dd51ecd57f51fff87aefced0bc9d47
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:c7505272fb0210461f5b388b86ff12702ea2bf42eab869d789afbe118b4385d6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:15aefd9556e33989c4b13d306f3acd83360832a8766f9b3124cd0f257e59fb4d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:8d361c7c2320da3aa1250b9a8798cad9dd225837969b1a8411672a1331810d03
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:751a8e8423c63aa99f12c034f9f272f59a2fd62dfa4cef8bc03f97d061f93602