Sign inSign up
Python

dhi.io/python

Python 3.14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

3-alpine-fips-dev, 3-alpine3.24-fips-dev, 3.14-alpine-fips-dev, 3.14-alpine3.24-fips-dev, 3.14.7-alpine-fips-dev, 3.14.7-alpine3.24-fips-dev

Index digest:

sha256:2de70cc6832b1e74eb4999fef1150051d72f5d44aebd8219efd9fee8a37b4ebe

Manifest digest:

sha256:a9c115649657834b26a3f0202518a63ce3f682c9a4968f70488d7942e0c90fa7

Size

135.12 MB

Last pushed

2 days ago

Vulnerabilities

0
1
2
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:3c712314be8e001624b74c7f4d159a59424977622b37045dc9165d7df26c8870
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:5a452b0558cd86c3a2462c4e0d5d79c868c341d995cdbcf643fdb0aa0e4593c1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/python@sha256:cbed0f64797be8c731582e819509f880fcda5a7c5ffb4879499a9a7e257b3661
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:b754110143831ed3071a21d09fe32e4a0e80969ec073ebcadbb8c98c9132587b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/python@sha256:f57517d28f0e7fc1d1aac6b1bcc7e8513249d02b7443adc18d559d39bafe06d6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:0f44b5e97ca049002115099c307499738dccc9b32fd7aa8e3c69644bb6ecf17f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:a640cdfa648ab1a0958feec22d2276e4bee51d1c8f4b3c59a07119c6456a90ec
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:94a48a53e76e8d0b8375d81c675d41991a1e3d9383d24ce91a3eaa30916811f4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:ab5d11532a9a94c57933d0a008cc1449d1e133db65b04cef3f45a0509b9c5095
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:41278e96b969e2fd9b7dfc2772db7852b58470831ef37407b0f5cb0388ea97f9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:d8ed65a73bf8a7d34710f05e4042dfd3a4516e88d726cba68b1ae9cb326a0933
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:c354d71a03ef0d9e31f01968f3c24e515b11380e70be0ba4c14d32df7366c558
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:bca553c1d1e656af0b4deca971f494833fc9dbcef2cecd139b40b620769fdbe9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:a2a309a94a239ac4685fc7afb2bf74856114a8ac78284d3981938f038953ef78
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:45b6cdfedc53506e467201cb575d957dd124cce9d9ab7419e7e8b2b0c3700e12
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:eda768754a07f1af246be5a9ac27278092d8f82db30bb00fae2006f355c72b00