Sign inSign up
Python

dhi.io/python

Python 3.14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

3-alpine-fips-dev, 3-alpine3.24-fips-dev, 3.14-alpine-fips-dev, 3.14-alpine3.24-fips-dev, 3.14.7-alpine-fips-dev, 3.14.7-alpine3.24-fips-dev

Index digest:

sha256:9e71f6fcb69686ad19f43345ddb90bf8cfe907820653edcf0866f17cc2812aa5

Manifest digest:

sha256:a90c69ac3cb9cc8ea5c047f9622df585b837b1db2fd24bcb28f2578bbf124817

Size

135.12 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:57d537c0e883a899a48deb7097cde9d4ee239f3007169b471d22e08f1728e891
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:49a6d7bdc2a9f4261d6d495516e4f394efd9259b21e1a063b703c96c98e82c91
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/python@sha256:5b59fa78d807e83ee166a8bec436dc9c90217311781b7f3719bd181cf1eca422
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:7d5cc226b084f37a45043f1c2144c8edf79d9f7a904bb4cad52c08138eb49c65
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/python@sha256:9c36066fb99990f628b9ee0d2aac4a1492b63249e4cbfa98b742cdf30ec96a3e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:38d6bd718051e5e7287ec02d26eb8f665da0e86f4f4305a8cdc6c3aaef2e0ef8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:393bca987188db32d1a83786cb1ba7f2840d8599fb1cdc834f0567d4a1a6f482
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:9989d1a095cd38f874a873c81f9ed6c9c78d78e01c955111c6747d47f57a15fa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:e136e6971d8a99d8d83a43210d4dedef7f59bbfcd433fdc5e640b88d078da8fb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:1577dc469f3d31a3a8619d1dc416d78edbd5c1d826098e8a0e9f06164cf9c717
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:4bd6e387581d34232c4db7f090d63f35ae8fa520d9e52d8b4502534ce2d66f80
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:03c1cbbee11e2c2702b9bfeb28a90f3738b8eac8e75a8006b94f8e9b415b625a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:339d5e0a473cbd73552c7dacdac3b799f14a7a414f09d7a1ce8ee018813af373
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:faf5f7e6daec87c823a1a316514f4cb46b570151e919ddcca391053d3e1e06c1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:34ff8d7d5d1860a34595b013a90142772fc6a9f7047ae407380168f7e3190be8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:8dfde00e65294743487e16f698f74c438239442c0c9a4c6822637387a07507bb