Sign inSign up
Python

dhi.io/python

Python 3.14.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

3-alpine-dev, 3-alpine3.24-dev, 3.14-alpine-dev, 3.14-alpine3.24-dev, 3.14.7-alpine-dev, 3.14.7-alpine3.24-dev

Index digest:

sha256:7041921325cdec555e8daf4c1b01c0caf2e09bd0eb15748d55b42e4aa0516324

Manifest digest:

sha256:5b4a133383d131dc65423d0fb12a5a90716872b340088e5b00f6050b4f71aae5

Size

81.25 MB

Last pushed

4 days ago

Vulnerabilities

0
0
2
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:4cc5b89ae07a32a55393bc79b26098eeaa9526685e182fcf656dfaf0916c3ac5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:8dc22085b0692ad79b1f6f6345ff86167edb35becfbf407e7dab95d1c94f7aee
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:adc3a877cc90ad60393d48cb36f84f2e4f0e8680c8f261438a25e168347d38c0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:f3793bb8c9e79930027bd5b06bb7a169017ec2c943e1197b1bb17d028ceadc05
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:ea635bb2c4d4d246b5b91c5f9e305ee231f74d1277bc4bfd5d7f99a1b15f6a27
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:1b38ac2bad4612dce81806429b0b549ca7d2a844f4b9e235332d232ae9f37b1c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:3fdbb6cd2bf1d46317c978f19ae9f5c9a92131279d4c7ca7371ef3594704b8c3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:6a7ffe59df225b16499869eda3deebdcb4d946e1549103c8e46f78d0be4390ea
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:852d29bcf213e28b1cb2ac543a7effff9a964220b1b6c22c9eb0b8a6fe098986
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:9efc5a466c3c103eba18f055fe84e4fb8213eeaa597d676114cf8407be262536
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:6f43d88321a928a4b519944884e05d622476ac0af1b4f8eaffd5129d548c4d34
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:dd656502635369667d3fe09f5f60351fc6c9b4666d90f14e935a6d5cf0d1e7d6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:f6455d9701cc0a560f05158f6dbe47db257654a60f0085bac7c3dfa7ea187911
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:a129bc1bdf59ab56e4ba5af6fbf1f09b76645185d1f3cc97307a66c1d7b63ef7