Sign inSign up
Python

dhi.io/python

Python 3.14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

3-alpine-fips-dev, 3-alpine3.24-fips-dev, 3.14-alpine-fips-dev, 3.14-alpine3.24-fips-dev, 3.14.7-alpine-fips-dev, 3.14.7-alpine3.24-fips-dev

Index digest:

sha256:128341d4043d64bc17cd33d47e2c6658a78af9ae15c954c1abd991eedb91bab0

Manifest digest:

sha256:f971d09d35362839e82bc4ceb8215888783b427523b78272583bec57871dca40

Size

135.07 MB

Last pushed

4 days ago

Vulnerabilities

0
0
2
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:d0d2117f2f49c8f54a7989d28c58c170e84fed30b041fef95dc141c4978d907f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:a829b60a2fafa8a4cba4e3951763194f3ad93fde6de5b7e21b7c19f6edc8d2b1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/python@sha256:2c77ded93e0ee730e5bb3781f2033b74dbe04df8fe160a535bae18c3bbbd953d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:06a240d09aabaf96b3d0ef1ed400d7cc128f1f3b2757abdafeed2973ffb068f3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/python@sha256:fe060e9ea3b3c3626eff7ef58e8312ce80c759f43b9f9c7b53060b038dc29c0d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:8aa972d0cfdbe92cf80a8c48688ea8020d80e6cc8653874d46b5add75ec58288
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:ecae5d5c5a22731cae61bb2bcc0145eeb0a2ae7437f2c8ebf4c71359fa2d693f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:32a97bcebb045007a655d13d59fbdd0c17e7fa0fe68691a4c2d815d0b1c4b9f9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:515c8543337cf0ed8bafd0bb3a8120ee069b596a257a7744f11e7727585c4e90
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:d4a9ec2a1e8b53fa5cd9758a8c125c2c799f95da1bd4bc6b5376711491fedc77
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:7e53622d60cc2d61debefaaedeebb393acf6ef04f43ba197b54e78e5e35f01f0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:b3051c38d3c28698e4d4b9536160cfe3da0ffe1839b088310c170f277126e7f3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:4bbf2f6577a127dfa25eebf82f77c0c7133b4db7536fff3e9591e5ea71071ab0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:22d3ca9a8dab1bafd8506ee80500dd76a489ad7426be0efefbc20a07c0edb6ef
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:fa520d62dc968863047d1eb6073d0c81e9ca1c27c370ffed5a41b70e4f4b9cfb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:34cc49cd14a8016c124c283f6457f99b78b5c13681baf693f3cc8092307c90fb